Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

216 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)4.8%—Larts Uploader Activex Control3/12/200916/6/2026
Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value.
ModificadaAlta (10)6.4%—Tibco Enterprise Message ServiceTibco RtworksTibco SmartsocketsTibco Smartsockets Rtserver30/4/200916/6/2026
Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and…
ModificadaAlta (10)7.1%💥 ExploitMicrosmarts Zipitfast!24/3/200916/6/2026
MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that triggers memory corruption, related to a "format string buffer overflow." NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.
ModificadaAlta (9.3)4.6%—Rimarts Becky! Internet Mail13/2/200916/6/2026
Buffer overflow in Becky! Internet Mail 2.48.02 and earlier allows remote attackers to execute arbitrary code via a mail message with a crafted return receipt request.
ModificadaMedia (4.3)2.1%💥 ExploitInfosoftglobal Fusion Charts5/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the dataURL parameter.
ModificadaAlta (7.5)1.1%💥 ExploitSmartsitecms3/2/200916/6/2026
SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter.
ModificadaMedia (4.3)1.2%—Portalparts Forum Plugin25/7/200816/6/2026
Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc.
ModificadaMedia (4.3)1.5%💥 ExploitGeertsen Holdings INC Geecarts2/4/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)1.1%—Geertsen Holdings INC Geecarts2/4/200816/6/2026
Multiple PHP remote file inclusion vulnerabilities in GeeCarts allow remote attackers to execute arbitrary PHP code via a URL in the id parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.5%💥 ExploitSmartscript Domain Trader12/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action.
ModificadaAlta (10)5.5%—Tibco RtworksTibco Smartsockets RtserverTibco Enterprise Message Service16/1/200816/6/2026
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers.
ModificadaAlta (10)6.4%—Tibco Enterprise Message ServiceTibco RtworksTibco Smartsockets Rtserver16/1/200816/6/2026
Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-length values that trigger the overflow.
ModificadaAlta (10)5.5%—Tibco RtworksTibco Smartsockets RtserverTibco Enterprise Message Service16/1/200816/6/2026
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.
ModificadaAlta (10)5.4%—Tibco Enterprise Message ServiceTibco RtworksTibco Smartsockets Rtserver16/1/200816/6/2026
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted requests that control loop operations related to memory.
ModificadaMedia (6.8)31%💥 ExploitElectronic Arts Snoopyctrl9/10/200716/6/2026
Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters.
ModificadaAlta (7.5)1.5%—Smartsitecms2/3/200716/6/2026
admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie.
ModificadaMedia (6.8)2.4%💥 ExploitMxbb Charts20/12/200616/6/2026
PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.
ModificadaMedia (5.1)4.2%💥 ExploitSmartsitecms7/7/200616/6/2026
PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a…
ModificadaAlta (7.8)2.0%—Electronic Arts Nascar Racing6/7/200616/6/2026
Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD asynchronous socket.
ModificadaAlta (7.5)7.1%💥 ExploitSmartsitecms22/6/200616/6/2026
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
ModificadaAlta (7.8)0.39%—KDE Arts15/6/200616/6/2026
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.
ModificadaMedia (5)2.6%—Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+62/5/200516/6/2026
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data.
ModificadaAlta (7.5)1.3%—Ecommerce-carts Ecommpro2/5/200516/6/2026
SQL injection vulnerability in login.asp for Ecommerce-Carts EcommPro 3.0 allows remote attackers to execute arbitrary SQL commands via the password field.
ModificadaMedia (5)4.3%💥 ExploitLucasarts Star Wars Jedi Knight Jedi Academy2/5/200516/6/2026
Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell.
ModificadaMedia (5)3.4%💥 ExploitLucasarts Star Wars Battlefront10/1/200516/6/2026
Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.
Orbitaley — Vulnerabilidades