Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1781 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)72%💥 ExploitSeattle LAB Software Slmail27/5/200316/6/2026
Múltiples desbordamientos de búfer en SLMail 5.1.0.4420 permite que atacantes remotos ejecuten código arbitrario mediante (1) un argumento EHLO largo a slmail.exe, (2) un argumento XTRN largo a slmail.exe, (3) una cadena larga para POPPASSWD, o (4) un password largo para el servidor POP3.
ModificadaAlta (7.5)1.2%💥 ExploitBattleaxe Software Bttlxeforum12/5/200316/6/2026
Vulnerabilidad de inyección de SQL en bttlxeForum 2.0 beta 3 y anteriores permite a atacantes remotos saltarse la autenticación mediante los campos de nombre de usuario y contraseña, y posiblemente otros campos.
ModificadaMedia (6.8)3.5%💥 ExploitJohn Beatty Easy PHP Photo Album11/5/200316/6/2026
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
ModificadaMedia (5)1.8%—ATT VNCTightvnc3/3/200316/6/2026
The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies.
ModificadaMedia (6.8)2.0%💥 ExploitAtthat.com Thatware31/12/200216/6/2026
PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
ModificadaAlta (7.5)2.7%—Matt Wright Formmail31/12/200216/6/2026
Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname)…
ModificadaMedia (4.6)0.31%—Iomega Network Attached Storage31/12/200216/6/2026
Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled.
ModificadaAlta (7.5)1.1%—Atthat.com Thatware31/12/200216/6/2026
SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter.
ModificadaMedia (6.8)1.3%—Atthat.com Thatware31/12/200216/6/2026
PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
ModificadaMedia (6.8)1.3%—Atthat.com Thatware31/12/200216/6/2026
PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter.
ModificadaMedia (5)1.4%—Matt Wright Formmail31/12/200216/6/2026
Matt Wright FormMail 1.9 and earlier allows remote attackers to send spam or anonymous e-mail by injecting a newline character followed by CC:, BCC:, or additional TO: fields in the email and realname CGI variables.
ModificadaMedia (5)1.7%—Matthew Smith Micq23/12/200216/6/2026
mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character.
ModificadaAlta (7.5)7.2%💥 ExploitSplatt Forum4/10/200216/6/2026
Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script.
ModificadaAlta (7.5)3.4%—Matthew Mondor MmftpdMatthew Mondor Mmmail4/10/200216/6/2026
Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.
ModificadaMedia (5)1.5%—Michael Dean Double Choco Latte4/10/200216/6/2026
Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features.
ModificadaMedia (5)1.9%—Michael Dean Double Choco Latte4/10/200216/6/2026
Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features.
ModificadaMedia (5)1.9%—Michael Dean Double Choco Latte4/10/200216/6/2026
Directory traversal vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to read arbitrary files via .. (dot dot) sequences when downloading files from the Projects: Attachments feature.
ModificadaMedia (4.6)0.40%—ATT Winvnc ServerTightvncTridiavnc24/9/200216/6/2026
Vulnerabilidad en VNC, TightVNC, y TridiaVNC permite a usuarios locales ejecutar código arbitrario como LocalSystem usando el sistema de mensajes de Win32 para evitar el GUI (Interfaz Gráfico de Úsuario) y acceder al cuadro de diálogo "Añadir nuevos clientes"
ModificadaAlta (7.5)4.1%—Matt Blaze CFS25/6/200216/6/2026
Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaAlta (7.5)2.7%—Noah Gray Graymatter25/6/200216/6/2026
Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server…
ModificadaAlta (7.5)1.9%—Matt Wright Pgpmail.pl30/11/200116/6/2026
PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters.
ModificadaAlta (7.5)1.9%—Guiseppe Tanzilli AND Matthias Eckermann MOD Auth Pgsql29/8/200116/6/2026
The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.
ModificadaAlta (7.5)1.4%—Matt Wright Formmail22/8/200116/6/2026
FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters.
ModificadaAlta (7.5)17%💥 ExploitMatt Tourtillott Nph-maillist2/7/200116/6/2026
nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.
ModificadaMedia (5)6.5%💥 ExploitSilverplatter Webspirs2/6/200116/6/2026
Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.