Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)3.1%—Widelands5/12/201116/6/2026
The pathname canonicalization functionality in io/filesystem/filesystem.cc in Widelands before 15.1 expands leading ~ (tilde) characters to home-directory pathnames but does not restrict use of these characters in strings received from the network, which might allow remote attackers to conduct absolute path traversal…
ModificadaMedia (6.4)1.8%—Widelands5/12/201116/6/2026
Directory traversal vulnerability in io/filesystem/filesystem.cc in Widelands before 15.1 might allow remote attackers to overwrite arbitrary files via . (dot) characters in a pathname that is used for a file transfer in an Internet game.
ModificadaAlta (9.3)2.4%—Nasm Netwide Assembler8/9/200916/6/2026
Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors, a different vulnerability than CVE-2008-2719.
ModificadaMedia (6.8)10%💥 ExploitNasm Netwide Assembler16/6/200816/6/2026
Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted file that triggers a stack-based buffer overflow.
ModificadaAlta (10)2.6%—Aertherwide Exiftags18/12/200716/6/2026
Unspecified vulnerability in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355.
ModificadaAlta (10)2.1%—Aertherwide Exiftags18/12/200716/6/2026
Integer overflow in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6354.
ModificadaMedia (5)1.8%—Aertherwide Exiftags18/12/200716/6/2026
exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image.
ModificadaAlta (7.8)2.0%—Cisco Wide Area Application Services21/7/200716/6/2026
The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets…
ModificadaMedia (5)1.8%—Hitachi Groupmax Integrated DesktopHitachi Groupmax MailHitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB Desktop29/4/200616/6/2026
The Gmax Mail client in Hitachi Groupmax before 20060426 allows remote attackers to cause a denial of service (application hang or erroneous behavior) via an attachment with an MS-DOS device filename.
ModificadaMedia (5.8)1.3%—Hitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB DesktopHitachi Groupmax World Wide WEB Desktop SchedulerHitachi Groupmax World Wide WEB Scheduler1/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
ModificadaMedia (4.3)1.4%—Widexl Download Tracker18/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
ModificadaAlta (10)18%💥 ExploitNasm Netwide Assembler10/1/200516/6/2026
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.
ModificadaMedia (4)1.3%—Hitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB Desktop31/12/200416/6/2026
Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter.
ModificadaMedia (4.3)1.2%—Hitachi Groupmax World Wide WEB Desktop31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter.
Orbitaley — Vulnerabilidades