Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 3.1% | — | Widelands | 5/12/2011 | 16/6/2026 | The pathname canonicalization functionality in io/filesystem/filesystem.cc in Widelands before 15.1 expands leading ~ (tilde) characters to home-directory pathnames but does not restrict use of these characters in strings received from the network, which might allow remote attackers to conduct absolute path traversal… | |
| Modificada | Media (6.4) | 1.8% | — | Widelands | 5/12/2011 | 16/6/2026 | Directory traversal vulnerability in io/filesystem/filesystem.cc in Widelands before 15.1 might allow remote attackers to overwrite arbitrary files via . (dot) characters in a pathname that is used for a file transfer in an Internet game. | |
| Modificada | Alta (9.3) | 2.4% | — | Nasm Netwide Assembler | 8/9/2009 | 16/6/2026 | Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors, a different vulnerability than CVE-2008-2719. | |
| Modificada | Media (6.8) | 10% | 💥 Exploit | Nasm Netwide Assembler | 16/6/2008 | 16/6/2026 | Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted file that triggers a stack-based buffer overflow. | |
| Modificada | Alta (10) | 2.6% | — | Aertherwide Exiftags | 18/12/2007 | 16/6/2026 | Unspecified vulnerability in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355. | |
| Modificada | Alta (10) | 2.1% | — | Aertherwide Exiftags | 18/12/2007 | 16/6/2026 | Integer overflow in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6354. | |
| Modificada | Media (5) | 1.8% | — | Aertherwide Exiftags | 18/12/2007 | 16/6/2026 | exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image. | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Wide Area Application Services | 21/7/2007 | 16/6/2026 | The Common Internet File System (CIFS) optimization in Cisco Wide Area Application Services (WAAS) 4.0.7 and 4.0.9, as used by Cisco WAE appliance and the NM-WAE-502 network module, when Edge Services are configured, allows remote attackers to cause a denial of service (loss of service) via a flood of TCP SYN packets… | |
| Modificada | Media (5) | 1.8% | — | Hitachi Groupmax Integrated DesktopHitachi Groupmax MailHitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB Desktop | 29/4/2006 | 16/6/2026 | The Gmax Mail client in Hitachi Groupmax before 20060426 allows remote attackers to cause a denial of service (application hang or erroneous behavior) via an attachment with an MS-DOS device filename. | |
| Modificada | Media (5.8) | 1.3% | — | Hitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB DesktopHitachi Groupmax World Wide WEB Desktop SchedulerHitachi Groupmax World Wide WEB Scheduler | 1/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.4% | — | Widexl Download Tracker | 18/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | |
| Modificada | Alta (10) | 18% | 💥 Exploit | Nasm Netwide Assembler | 10/1/2005 | 16/6/2026 | Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194. | |
| Modificada | Media (4) | 1.3% | — | Hitachi Groupmax World Wide WEBHitachi Groupmax World Wide WEB Desktop | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Groupmax World Wide Web (GmaxWWW) 2 and 3, and Desktop 5, 6, and Desktop for Jichitai allows remote authenticated users to read arbitrary .html files via the template name parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Hitachi Groupmax World Wide WEB Desktop | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web (GmaxWWW) Desktop 5, 6, and Desktop for Jichitai 6, allows remote attackers to inject arbitrary web script or HTML via the QUERY parameter. |