Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 3.4% | — | Kyoceramita Scanner File Utility | 28/8/2009 | 16/6/2026 | The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it easier for remote attackers to execute arbitrary code or overwrite files by leveraging CVE-2008-7110 and CVE-2008-7109. | |
| Modificada | Alta (7.8) | 2.9% | 💥 Exploit | Kyoceramita Scanner File Utility | 28/8/2009 | 16/6/2026 | Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (dot dot) in a request. | |
| Modificada | Crítica (9.8) | 4.1% | — | Kyoceramita Scanner File Utility | 28/8/2009 | 16/6/2026 | The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user for a password. | |
| Modificada | Media (6.9) | 0.30% | — | Mailscanner | 3/12/2008 | 16/6/2026 | mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and (4) f-prot-6-autoupdate scripts in /etc/MailScanner/autoupdate/; the (5)… | |
| Modificada | Media (6.9) | 0.30% | — | Mailscanner | 3/12/2008 | 16/6/2026 | mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new, (4) trend-autoupdate.new, and (5) rav-autoupdate.new scripts in… | |
| Modificada | Media (6.9) | 0.33% | — | Debian Mailscanner | 18/11/2008 | 16/6/2026 | trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/opr.ini.##### or (2) /tmp/lpt*.zip temporary file. | |
| Modificada | Media (4.3) | 1.1% | — | Internet Security Systems Internet Scanner | 29/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the report interface in Internet Security Systems (ISS) Internet Scanner 7.0 Service Pack 2 Build 7.2.2005.52 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 8.1% | 💥 Exploit | Bitdefender Online Anti-virus Scanner | 30/11/2007 | 16/6/2026 | A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper… | |
| Modificada | Alta (9.3) | 4.8% | — | Kaspersky LAB Online Scanner | 12/10/2007 | 16/6/2026 | Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute arbitrary code via format string specifiers in "various string formatting functions," which trigger heap-based buffer overflows. | |
| Modificada | Alta (7.8) | 2.1% | 💥 Exploit | Nessus Vulnerability Scanner | 30/7/2007 | 16/6/2026 | The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via unspecified vectors involving the deleteNessusRC method, probably a directory traversal vulnerability. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Nessus Vulnerability Scanner | 30/7/2007 | 16/6/2026 | Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument to the saveNessusRC method, which writes text specified by the addsetConfig method, possibly related to the… | |
| Modificada | Alta (7.8) | 5.7% | 💥 Exploit | Nessus Vulnerability Scanner | 27/7/2007 | 16/6/2026 | Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attackers to delete arbitrary files via a .. (dot dot) in the argument to the deleteReport method, probably related to the SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll. | |
| Modificada | Alta (7.8) | 2.1% | — | Amavis Virus ScannerGentoo File | 13/4/2007 | 16/6/2026 | The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS. | |
| Modificada | Baja (1.9) | 1.8% | 💥 Exploit | Acunetix WEB Vulnerability Scanner | 9/1/2007 | 16/6/2026 | Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of service (application crash) via multiple HTTP requests containing invalid Content-Length values. | |
| Modificada | Alta (10) | 7.4% | — | Softwin BitdefenderSoftwin Bitdefender AntivirusSoftwin Bitdefender Internet SecuritySoftwin Bitdefender Mail Protection+1 | 18/12/2006 | 16/6/2026 | Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to… | |
| Modificada | Alta (10) | 1.4% | — | Paisterist Simple Http Scanner | 27/9/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.3 have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 1.4% | — | Paisterist Simple Http Scanner | 27/9/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.2 have unknown impact and attack vectors. | |
| Modificada | Crítica (9.8) | 1.8% | — | Paisterist Simple Http Scanner | 27/9/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Paisterist Simple HTTP Scanner (sHTTPScanner) before 0.4 have unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Mailscanner | 2/11/2005 | 16/6/2026 | SQL injection vulnerability in in the authenticate function in MailWatch for MailScanner 1.0.2 allows remote attackers to execute arbitrary SQL commands. | |
| Modificada | Media (5) | 1.7% | — | Mailwatch FOR MailscannerAI | 2/11/2005 | 16/6/2026 | Directory traversal vulnerability in the ruleset view for MailWatch for MailScanner 1.0.2 allows remote attackers to access arbitrary files. | |
| Modificada | Alta (7.5) | 1.4% | — | Mailscanner | 24/5/2005 | 16/6/2026 | Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection. | |
| Modificada | Media (4.6) | 0.42% | — | GFI Languard Network Security Scanner | 2/5/2005 | 16/6/2026 | lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials. | |
| Modificada | Media (5) | 1.6% | — | F-secure Anti-virusF-secure Content Scanner ServerF-secure Internet Gatekeeper | 9/9/2004 | 16/6/2026 | The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain… | |
| Modificada | Media (6.4) | 1.1% | — | Mailscanner | 31/12/2002 | 16/6/2026 | MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by MailScanner. | |
| Modificada | Alta (7.5) | 2.3% | — | Virgil CGI Scanner | 31/12/2002 | 16/6/2026 | Virgil CGI Scanner 0.9 allows remote attackers to execute arbitrary commands via the (1) tar (TARGET) or (2) zielport (ZIELPORT) parameters. |