Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1918 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.6)5.0%—Smartftp31/12/200316/6/2026
Multiple buffer overflows in SmartFTP 1.0.973, and other versions before 1.0.976, allow remote attackers to execute arbitrary code via (1) a long response to a PWD command, which triggers a stack-based overflow, and (2) a long line in a response to a file LIST command, which triggers a heap-based overflow.
ModificadaAlta (7.5)4.0%—Smartmax Software Mailmax9/6/200316/6/2026
Desbordamiento de búfer en el servidor IMAP (IMAPMAX) para SmartMax MailMax 5.0.10.8 y anteriores permite que usuarios remotos autentificados ejecuten código arbitrario mediante el comando "SELECT".
ModificadaMedia (5)7.0%💥 ExploitEnterasys Smartswitch Ssr80002/4/200316/6/2026
La funcionalidad MPS en Enterasys SSR8000 (Smart Switch Router) con firmware anterior a 8.3.0.10 permite a atacantes remotos causar una denegación de servicio (caída) mediante múltiples escaneos de puertos a puertos 15077 y 15078.
ModificadaMedia (5)3.0%💥 ExploitVirtualzone Smartmail Server31/12/200216/6/2026
SmartMail Server 2.0 allows remote attackers to cause a denial of service (crash) by sending data and closing the connection before all the data has been sent.
ModificadaMedia (5)3.3%💥 ExploitVirtualzone Smartmail Server31/12/200216/6/2026
Buffer overflow in SmartMail Server 1.0 Beta 10 allows remote attackers to cause a denial of service (crash) via a long request to (1) TCP port 25 (SMTP) or (2) TCP port 110 (POP3).
ModificadaAlta (7.5)9.9%💥 ExploitSmartmax Software Mailmax4/10/200216/6/2026
Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command.
ModificadaMedia (6.2)0.44%—HP Photosmart Print Driver12/8/200216/6/2026
HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain privileges of other Photosmart users by replacing hp_imaging_connectivity with a Trojan horse.
ModificadaBaja (2.1)0.37%—Centra ASPCentraoneCentra Smart Connect31/12/200116/6/2026
CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.
ModificadaAlta (7.5)7.5%💥 ExploitNetscape Smartdownload2/7/200116/6/2026
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
ModificadaAlta (7.2)0.39%—Smartstuff Foolproof Security16/2/200116/6/2026
FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them.
ModificadaMedia (5)7.9%💥 ExploitSmartwin Technology Cyberoffice Shopping Cart19/12/200023/9/2026
La instalación predeterminada de SmartWin CyberOffice Shopping Cart 2 (también conocido como CyberShop) instala el directorio _private con permisos de lectura para todos, lo que permite a atacantes remotos obtener información sensible.
ModificadaAlta (7.5)7.0%💥 ExploitSmartwin Technology Cyberoffice Shopping Cart19/12/200025/9/2026
SmartWin CyberOffice Shopping Cart 2 (también conocido como CyberShop) permite a atacantes remotos modificar información de precios cambiando la variable de formulario oculta 'Price'.
ModificadaBaja (2.1)0.48%—Mindstorm Smartftp Daemon13/6/200016/6/2026
SmartFTP Daemon 0.2 allows a local user to access arbitrary files by uploading and specifying an alternate user configuration file via a .. (dot dot) attack.
ModificadaAlta (7.5)2.1%—Netsmart Smartcart1/2/200016/6/2026
The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
ModificadaMedia (5)1.1%—Cabletron Smartswitch Router 8000 Firmware24/11/199916/6/2026
Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.
ModificadaMedia (4.6)0.35%—Compaq Smartstart2/9/199916/6/2026
Compaq Integration Maintenance Utility as used in Compaq Insight Manager agent before SmartStart 4.50 modifies the legal notice caption (LegalNoticeCaption) and text (LegalNoticeText) in Windows NT, which could produce a legal notice that is in violation of the security policy.
ModificadaMedia (5)5.2%💥 ExploitSmartdesk Websuite23/5/199916/6/2026
Buffer overflow in SmartDesk WebSuite allows remote attackers to cause a denial of service via a long URL.
ModificadaAlta (7.5)9.8%💥 ExploitSmartmax Software Mailmax14/2/199916/6/2026
Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
Orbitaley — Vulnerabilidades