Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1756 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Mobilelib Gold | 31/12/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en el contact_us.php del ac4p Mobilelib gold 2 permiten a atacantes remotos la inyección de secuencias de comandos web o HTML de su elección mediante el parámetro (1) email o (2) errr. | |
| Modificada | Alta (10) | 31% | — | Broadcom Widcomm BluetoothMicrosoft Windows Embedded CompactMicrosoft Windows Mobile | 31/12/2006 | 16/6/2026 | Desbordamiento de búfer en la el Servidor COM de Pila Bluetooth de la pila Bluetooth Widcomm, empaquetada en Pila Widcomm 3.x y anteriores en Windows, Widcomm BTStackServer 1.4.2.10 y 1.3.2.7 en Windows, Widcomm Bluetooth Communication Software 1.4.1.03 en Windows, y la implementación de Bluetooth en Windows Mobile o… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Ac4p Mobile | 8/12/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en ac4p Mobile permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro (1) Taaa de (a) up.php, o los parámetros (2) pollhtml y (3) Bloks de (b) polls.php, vectores distintos de… | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Realnetworks Helix DNA ServerRealnetworks Helix Mobile ServerRealnetworks Helix Server | 21/11/2006 | 16/6/2026 | Desbordamiento de búfer basado en montículo en Helix DNA Server 11.0 y 11.1 tiene impacto y vectores de ataque desconocidos, como ha sido demostrado por cierto módulo de VulnDisco Pack. NOTA: la procedencia de esta información es desconocida; los detalles han sido obtenidos únicamente de información de terceros. Desde… | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Ac4p Mobile | 6/11/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en ac4p Mobile permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante los parámetros (1) Bloks, (2) Newnews, (3) lBlok, y (4) foooot en (a) index.php; los parámetros Newnews, (5) newmsgs, y Bloks en… | |
| Modificada | Alta (7.5) | 1.2% | — | Mobilesecure INC Highwall EndpointMobilesecure INC Highwall Enterprise | 6/11/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en la interfaz de administración de Highwall Enterprise y Highwall Endpoint 4.0.2.11045 permite a atacantes remotos ejecutar comandos SQL de su elección mediante un Punto de Acceso con un SSID manipulado, y a través de vectores no especificados relacionados con un operador… | |
| Modificada | Media (4.3) | 1.2% | — | Mobilesecure Highwall EndpointMobilesecure Highwall Enterprise | 6/11/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en la interfaz de administración Highwall Enterprise y Highwall Endpoint 4.0.2.11045 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de (1) un Punto de Acceso con un SSID manipulado, (2) el… | |
| Modificada | Media (5.1) | 1.3% | — | Mobilesecure INC Highwall EndpointMobilesecure INC Highwall Enterprise | 20/10/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en la interfaz de dirección del IDS wireless para Highwall Enterprise and Highwall Endpoint 4.0.2.11045 permite a un atacante remoto inyectar HTML de su elección o secuencias de comandos web a través de vectores no especificados. | |
| Modificada | Alta (7.5) | 1.3% | — | Mobilesecure INC Highwall EndpointMobilesecure INC Highwall Enterprise | 20/10/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en la interfaz de dirección de IDS wireless para Highwall Enterprise and Highwall Endpoint 4.0.2.11045 permite a un atacante remooto ejecutar comandos SQL de su elección a través de vectores no especificados. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Mobilepublisherphp | 19/9/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en header.php en MobilePublisherPHP 1.5 RC2 y anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro abspath. | |
| Modificada | Media (4.9) | 0.43% | — | Shape Services IM+ Mobile Instant Messenger | 7/9/2006 | 16/6/2026 | Shape Services IM+ Mobile Instant Messenger para Pocket PC 3.10 almacena nombres de usuario y contraseñas en texto plano en %PROGRAMFILES%\IMPlus\implus.cfg, lo cual permite a un usuario local obtener información sensible a través de la lectura del fichero. | |
| Modificada | Media (6.8) | 1.4% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | Vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en index.php en MobeScripts Mobile Space Community v2.0 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro a (1)mostrar parámetros, que no se filtra en el error resultante y… | |
| Modificada | Alta (7.5) | 1.8% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | Vulnerabilidad de salto de directorio en MobeScripts Mobile Space Community 2.0, permite a atacantes remotos incluir y ejecutar ficheros locales de su elección al utilizar caracteres .. (punto punto) en el parámetro uid de la página de RSS. | |
| Modificada | Alta (7.5) | 1.3% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en index.php en MobeScripts Mobile Space Community v.2.0 permite a atacantes remotos ejecutar comandos SQL a través del parámetro Browse. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+3 | 19/1/2006 | 16/6/2026 | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business… | |
| Modificada | Media (5) | 3.8% | — | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+3 | 19/1/2006 | 16/6/2026 | The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection… | |
| Modificada | Media (5) | 1.6% | — | Dell Truemobile 2300 Wireless Broadband Router | 8/12/2005 | 16/6/2026 | Dell TrueMobile 2300 Wireless Broadband Router running firmware 3.0.0.8 and 5.1.1.6, and possibly other versions, allows remote attackers to reset authentication credentials, then change configuration or firmware, via a direct request to apply.cgi with the Page parameter set to adv_password.asp. | |
| Modificada | Media (5) | 1.5% | — | Captaris Infinite Mobile Delivery Webmail | 2/5/2005 | 16/6/2026 | Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.3% | — | Captaris Infinite Mobile Delivery Webmail | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Media (5) | 1.6% | — | LG Electronics LG Mobile Phone | 2/5/2005 | 16/6/2026 | LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file. | |
| Modificada | Media (4.6) | 0.44% | — | Esesix Thintune ExtremeEsesix Thintune LEsesix Thintune MEsesix Thintune Mobile+3 | 31/12/2004 | 16/6/2026 | eSeSIX Thintune thin clients running firmware 2.4.38 and earlier allow local users to gain privileges by pressing CTRL-SHIFT-ALT-DEL and entering the "maertsJ" password, which is hard-coded into lshell. | |
| Modificada | Alta (10) | 3.1% | — | Esesix Thintune ExtremeEsesix Thintune LEsesix Thintune MEsesix Thintune Mobile+3 | 31/12/2004 | 16/6/2026 | radmin in eSeSIX Thintune thin clients running firmware 2.4.38 and earlier starts a process port 25072 that can be accessed with a default "jstwo" password, which allows remote attackers to gain access. | |
| Modificada | Media (4.6) | 0.36% | — | Esesix Thintune ExtremeEsesix Thintune LEsesix Thintune MEsesix Thintune Mobile+3 | 31/12/2004 | 16/6/2026 | eSeSIX Thintune thin clients running firmware 2.4.38 and earlier store sensitive usernames and passwords in cleartext in configuration files for the keeper library, which allows attackers to gain access. | |
| Modificada | Alta (10) | 5.6% | 💥 Exploit | Dell Truemobile 1300 Wlan Mini-pci Card Util Trayapplet | 31/12/2004 | 16/6/2026 | Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality. | |
| Modificada | Media (5) | 27% | — | Nortel IP Softphone 2050Nortel Mobile Voice Client 2050Nortel Optivity Telephony ManagerMicrosoft Windows 2000+5 | 15/12/2004 | 16/6/2026 | The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by… |