Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1924 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.2%—Phpbb Group Phpbb Plus2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52 and earlier allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3) portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c parameter to index.php, or (7) the article…
ModificadaAlta (7.2)0.37%—Webroot Software MY Firewall Plus10/1/200516/6/2026
The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before invoking help, which allows local users to gain privileges.
ModificadaBaja (2.1)0.47%—Broadcom Common ServicesBroadcom Unicenter Network AND Systems ManagementBroadcom Unicenter Serviceplus Service Desk31/12/200416/6/2026
Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges.
ModificadaMedia (5)1.5%—Follett Software Webcollection Plus31/12/200316/6/2026
Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter.
ModificadaMedia (4.6)0.33%—Splus S-plusAI31/12/200316/6/2026
S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6)…
ModificadaMedia (5)7.8%💥 ExploitCoxco Support A-cartCoxco Support MetacartCoxco Support Midicart ASPCoxco Support Midicart ASP Maxi+311/4/200316/6/2026
MidiCart almacena el fichero de base de datos midicart.mdb bajo la raíz de documentos web, lo que permite a atacantes remotos robar información sensible pidiendo la base de datos directamente.
ModificadaCrítica (9.1)4.6%💥 ExploitMidicart PHPMidicart PHP MaxiMidicart PHP Plus31/12/200216/6/2026
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php.
ModificadaMedia (5)1.2%—Uninet Statsplus31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers.
ModificadaMedia (5)4.2%—Microsoft Windows 98 Plus PackMicrosoft Windows MEMicrosoft Windows XP11/10/200216/6/2026
La característica de Carpetas Comprimidas en Microsoft Windows 98 con el paquete Plus!, Windows Me, y Windows XP no comprueba adecuadamente la carpeta de destino durante la descompresión de ficheros ZIP, lo que permite a atacantes remotos poner un fichero ejecutable en una lugar conocido en el sistema del usuario,…
ModificadaAlta (7.5)43%—Allume Systems Division Stuffit ExpanderIBM Lotus NotesVerity Keyview Viewing SDKWinzip+310/10/200216/6/2026
Desbordamiento de búfer en la capacidad ZIP de múltiples productos permite a atacantes remotos causar una denegación de servicio o ejecutar código arbitrario mediante ficheros ZIP que contienen nombres de ficheros largos, incluyendo Microsoft Windows 98 con el paquete Plus! Windows XP Windows Me Lotus Notes R4 a R6…
ModificadaAlta (7.5)2.0%—Realnetworks Realjukebox 2Realnetworks Realjukebox 2 PlusRealnetworks Realone Player4/10/200216/6/2026
RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by…
ModificadaAlta (7.5)8.1%💥 ExploitRealnetworks Realjukebox 2Realnetworks Realjukebox 2 PlusRealnetworks Realone Player4/10/200216/6/2026
Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image.
ModificadaAlta (7.5)2.4%—Mutasem Abudahab CsvformMutasem Abudahab Csvform Plus11/12/200116/6/2026
csvform.pl 0.1 permite a atacantes remotos la ejecución de comandos arbitrarios mediante el uso de metacaracteres en el fichero dado como parámetro.
ModificadaAlta (7.5)7.0%💥 ExploitIbill Internet Billing Company Processing Plus6/12/200116/6/2026
ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.
ModificadaAlta (7.5)2.1%—Kabotie Software Technologies Shopplus Cart5/9/200116/6/2026
shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter.
ModificadaAlta (7.5)1.8%—QPC Software QVT NETQPC Software QVT Term Plus2/7/200116/6/2026
Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.
ModificadaMedia (4.6)0.33%—Rediplus27/6/200116/6/2026
REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.
ModificadaBaja (2.1)8.9%—Microsoft Plus3/5/200116/6/2026
The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders.
ModificadaMedia (5)9.7%💥 ExploitNetcplus Browsegate19/12/200023/9/2026
BrowseGate 2.80 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar comandos arbitrarios a través de encabezados MIME largos de Authorization o Referer en la solicitud HTTP.
ModificadaBaja (3.6)0.74%💥 ExploitPlus Technologies Lpplus14/11/200016/6/2026
LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.
ModificadaBaja (2.1)0.42%—Plus Technologies Lpplus14/11/200016/6/2026
LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.
ModificadaBaja (2.1)0.87%💥 ExploitPlus Technologies Lpplus14/11/200016/6/2026
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.
ModificadaAlta (7.5)9.8%💥 ExploitPowerscripts Plusmail11/1/200016/6/2026
PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.
ModificadaAlta (7.5)12%💥 ExploitQPC Software QVT NETQPC Software QVT Term Plus10/11/199916/6/2026
Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.