Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3082▲ 502 respecto a la semana anterior
Críticas / altas1460▲ 59 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1973 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)26%—Microsoft Word12/7/200516/6/2026
Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.
ModificadaAlta (7.5)9.3%💥 ExploitWordpress5/7/200516/6/2026
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.
ModificadaMedia (5)2.9%—Wordpress5/7/200516/6/2026
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect…
ModificadaMedia (5)2.6%—Wordpress5/7/200516/6/2026
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.
ModificadaMedia (4.3)2.6%—Wordpress5/7/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.
ModificadaAlta (7.5)3.1%—Wordpress1/6/200516/6/2026
SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.
ModificadaBaja (2.6)15%—Microsoft Word20/5/200516/6/2026
Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
ModificadaAlta (7.5)2.3%—Wordpress20/5/200516/6/2026
SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.
ModificadaMedia (5.3)1.9%—Wordpress20/5/200516/6/2026
Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.
ModificadaMedia (6.8)2.9%—Wordpress2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.
ModificadaAlta (7.5)2.3%—Crosswire Bible Society Sword2/5/200516/6/2026
diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
ModificadaMedia (5.1)15%—Microsoft Word2/5/200516/6/2026
Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
ModificadaBaja (2.1)0.37%—Citrix Metaframe Password Manager2/5/200516/6/2026
Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.
ModificadaAlta (10)32%—Microsoft Word9/2/200516/6/2026
Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds…
ModificadaAlta (7.5)27%—Microsoft OfficeMicrosoft PowerpointMicrosoft ProjectMicrosoft Visio+28/2/200516/6/2026
Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.
ModificadaAlta (7.2)0.38%—Changepassword10/1/200516/6/2026
changepassword.cgi en ChangePassword 0.8, cuando se instala con setuid, permite a usuarios locales ejecutar código de su elección modifcando la variable de entorno PATH para que apunte a un programa "make" malicioso.
ModificadaMedia (4.3)6.5%💥 ExploitWordpress31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title…
ModificadaMedia (5)11%💥 ExploitWordpress31/12/200416/6/2026
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter.
ModificadaBaja (2.1)0.36%—Citrix Metaframe Password Manager31/12/200416/6/2026
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
ModificadaAlta (7.5)42%—Microsoft FrontpageMicrosoft OfficeMicrosoft PublisherMicrosoft Word+128/9/200416/6/2026
Desbordamiento de búfer en el convertidor de Microsoft WordPerfect 5.x en Office 2000, Office XP, Offiece 2003 y las suites Works 2001 a 2004 permite a atacantes remotos ejecutar código de su elección mediante un documento o un sitio web malicioso.
ModificadaAlta (9.3)49%💥 ExploitMicrosoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+2028/9/200416/6/2026
Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria.
ModificadaMedia (4.3)1.3%—WEB Animations Password Protect31/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter.
ModificadaAlta (7.5)1.2%💥 ExploitWEB Animations Password Protect30/8/200416/6/2026
SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp.
ModificadaAlta (10)8.4%—Abisource Community AbiwordWvware6/8/200416/6/2026
Desbordamiento de búfer en la función wvHandleDateTimePicture en la librería wv (wvWare) 0.7.4 a 0.7.6 y 1.0.0 permite a atacantes remotos ejecutar código de su elección mediante un documento con un campo DateTime largo.
ModificadaMedia (5)1.3%—Coffeecup Software Coffeecup Password Wizard31/12/200316/6/2026
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.