Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2886▲ 263 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1837 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.2%—Ktools29/11/200516/6/2026
Stack-based buffer overflow in kkstrtext.h in ktools library 0.3 and earlier, as used in products such as (1) centericq, (2) orpheus, (3) motor, and (4) groan, allows local users or remote attackers to execute arbitrary code via a long parameter to the VGETSTRING macro.
ModificadaAlta (7.5)1.2%—Onlinetechtools.com Owos Lite27/11/200516/6/2026
SQL injection vulnerability in search.asp in Online Work Order Suite (OWOS) Lite Edition for ASP 3.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
ModificadaMedia (4.3)1.2%—Onlinetechtools.com Okbsys Lite27/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in Online Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the q parameter.
ModificadaMedia (4.3)1.2%—Onlinetechtools.com Oasys Lite27/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.
ModificadaAlta (7.8)4.4%—Ipsec-tools21/11/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
ModificadaAlta (10)3.0%—Oracle PeopletoolsAIOracle Peoplesoft EnterpriseAI2/11/200516/6/2026
Vulnerabilidad no especificada en PeopleTools en Oracle PeopleSoft Enterprise 8.42 hasta la versión 8.45.17 tiene impacto y vectores de ataque no especificados, según lo identificado por Oracle Vuln# PSE01.
ModificadaAlta (7.5)5.5%💥 ExploitVirtools WEB Player4/10/200516/6/2026
Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename.
ModificadaMedia (5)2.1%—Virtools WEB Player4/10/200516/6/2026
Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.
ModificadaBaja (2.1)0.33%—Mpeg-tools30/9/200516/6/2026
mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN].
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaAlta (7.5)1.1%—Opentools Attachment MOD17/5/200516/6/2026
Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors.
ModificadaBaja (2.1)0.31%—Cdrtools Cdrecord2/5/200516/6/2026
cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaMedia (5)2.4%—Ipsec-toolsKame RacoonSGI PropackAltlinux ALT Linux+314/3/200516/6/2026
The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
ModificadaAlta (10)16%💥 ExploitMichael Kohn Ringtonetools10/1/200516/6/2026
Desbordamiento de búfer en la función parse_emelody en parse_emelody.c de ringtonetools 2.22 permite a atacantes ejecutar código de su elección mediante un fichero eMelody artesanal.
ModificadaAlta (7.2)1.7%💥 ExploitCdrtools Cdrecord31/12/200416/6/2026
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.
ModificadaMedia (5)1.9%—Smartertools Smartermail31/12/200416/6/2026
Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to read arbitrary files via the filename parameter.
ModificadaMedia (4)1.1%—Smartertools Smartermail31/12/200416/6/2026
frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability.
ModificadaBaja (3.6)0.63%💥 ExploitMtools Mformat31/12/200416/6/2026
MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.
ModificadaMedia (4.3)1.4%—Smartertools Smartermail31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to inject arbitrary web script or HTML via Javascript to the "check spelling" feature in the compose area.
ModificadaAlta (7.5)2.9%—Opentools Attachment MOD31/12/200416/6/2026
Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code.
ModificadaMedia (4.6)1.5%—Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+731/12/200416/6/2026
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not…
ModificadaAlta (7.8)1.8%—Smartertools Smartermail31/12/200416/6/2026
SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous open connections to TCP port 25.
ModificadaMedia (5)1.7%—Opentools Attachment MOD31/12/200416/6/2026
Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename.
ModificadaMedia (5)1.9%—Smartertools Smartermail31/12/200416/6/2026
login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a long txtusername parameter, possibly due to a buffer overflow.
ModificadaAlta (10)5.4%—Ipsec-toolsKame RacoonRedhat Enterprise LinuxRedhat Enterprise Linux Desktop6/12/200416/6/2026
La función eay_check_x509cert en KAME Racoon verifica como buenos certificados incluso cuando la validación OpenSLL falla, lo que podría permitir a atacantes remotos saltarse la autenticación.