Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.8%—Jake Olefsky Fotopholder21/8/200616/6/2026
Vulnerabilidad de escalado de directorio en index.php en Fotopholder 1.8 permite a atacantes remotos leer directorios de su elección o archivos mediante un .. (punto punto) en el parámetro path.
ModificadaAlta (7.5)67%💥 ExploitEFS Software EFS FTP Server1/8/200616/6/2026
Desbordamiento de búfer basado en pila en EFS Software Easy File Sharing FTP Server 2.0 permite a atacantes remotos ejecutar código de su elección a través de un argumento en el comando PASS. NOTA: la procedencia de esta información es desconocida; los detalles han sido obtenidos a partir de la información de terceros.
ModificadaAlta (7.5)4.0%—Greg Roelofs Libpng30/6/200616/6/2026
Desbordamiento de búfer en la función png_decompress_chunk en pngrutil.c en libpng anteriores a v1.2.12 permite a los atacantes dependientes de contexto causar una denegación de servicios y posiblemente ejecutar arbitrariamente código a través de vectores no especificado en relación a "error de procesamiento",…
ModificadaMedia (4.3)1.3%—EFS Software EFS WEB Server12/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to inject arbitrary web script or HTML via the Description field in creating a folder or uploading a file.
ModificadaAlta (7.8)6.8%💥 ExploitEFS Software EFS WEB Server12/3/200616/6/2026
Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the query string argument in an HTTP GET request.
ModificadaMedia (6.5)2.8%💥 ExploitEFS Software EFS WEB Server12/3/200616/6/2026
Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.
ModificadaAlta (7.5)2.8%—Fscripts Fantastic News10/3/200616/6/2026
PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable. NOTE: 2.1.4 was also reported to be vulnerable.
ModificadaMedia (5)1.3%💥 ExploitFscripts Fantastic News3/3/200616/6/2026
SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846.
ModificadaAlta (10)4.3%—Kyocera Fs-3830n19/2/200616/6/2026
Certain unspecified Kyocera printers have a default "admin" account with a blank password, which allows remote attackers to access an administrative menu via a telnet session.
ModificadaMedia (5)1.6%—Kyocera Fs-3830n19/2/200616/6/2026
Kyocera 3830 (aka FS-3830N) printers have a back door that allows remote attackers to read and alter configuration settings via strings that begin with "!R!SIOP0", as demonstrated using (1) a connection to to TCP port 9100 or (2) the UNIX lp command.
ModificadaAlta (10)1.7%—Noofs Team Network Object Oriented File System18/2/200616/6/2026
Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors.
ModificadaMedia (5)3.1%—Greg Roelofs Libpng31/1/200616/6/2026
Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image.
ModificadaAlta (7.5)1.3%💥 ExploitFscripts Fantastic News26/11/200516/6/2026
SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaMedia (4.6)0.60%—Greg Roelofs Pnmtopng18/11/200516/6/2026
Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors.
ModificadaMedia (5)3.0%💥 ExploitAfsl Games Battle Carry4/11/200516/6/2026
Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server's UDP port.
ModificadaMedia (5)2.7%💥 ExploitFsboard5/7/200516/6/2026
Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter.
ModificadaBaja (2.1)0.38%—Davfs231/5/200516/6/2026
WEB-DAV Linux File System (davfs2) 0.2.3 does not properly enforce Unix permissions, which allows local users to write arbitrary files on a davfs2 mounted filesystem.
ModificadaAlta (7.5)2.9%—Ncpfs2/5/200516/6/2026
Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.
ModificadaAlta (7.2)0.56%—Ncpfs2/5/200516/6/2026
nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
ModificadaBaja (2.1)1.1%💥 ExploitRuntime Software Getdataback FOR Ntfs2/5/200516/6/2026
GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information.
ModificadaAlta (7.2)0.40%—Ncpfs10/1/200516/6/2026
Desbordamiento de búfer en ncplogin y ncmap de nwclient.c de ncpfs 2.2.4, y posiblemente otras versiones, puede permitir a usuarios locales ganar privilegios mediante una opción -T larga.
ModificadaMedia (5)2.4%—Nfs-utilsDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+210/1/200516/6/2026
statd en nfs-utils 1.257 y anteriores hace caso a la señal SIGPIPE, lo que permite a atacanes remotos causar una denegación de servicio (caída de proceso de servidor) mediante una conexión TCP que es terminada prematuramente.
ModificadaAlta (10)6.0%—Dxfscope DXF File Format Viewer10/1/200516/6/2026
Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file.
ModificadaAlta (10)11%—Nfs-utilsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop10/1/200516/6/2026
rquotad en nfs-utils (rquota_server.c) anteriores a 1.0.6-r6 en arquitecturas de 64 bits no realiza una conversión de enteros adecuadamente, lo que conduce a un desbordamiento de búfer basado en la pila y permite a atacantes remotos ejecutar código arbitrario mediante una petición NFS artesanal.
ModificadaMedia (5)1.8%—FsphpgalleryAI31/12/200416/6/2026
Directory traversal vulnerability in index.php in FsPHPGallery before 1.2 allows remote attackers to list arbitrary directories via the dir parameter.