Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 4.8% | — | Larts Uploader Activex Control | 3/12/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value. | |
| Modificada | Alta (10) | 6.4% | — | Tibco Enterprise Message ServiceTibco RtworksTibco SmartsocketsTibco Smartsockets Rtserver | 30/4/2009 | 16/6/2026 | Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and… | |
| Modificada | Alta (10) | 7.1% | 💥 Exploit | Microsmarts Zipitfast! | 24/3/2009 | 16/6/2026 | MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that triggers memory corruption, related to a "format string buffer overflow." NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product. | |
| Modificada | Alta (9.3) | 4.6% | — | Rimarts Becky! Internet Mail | 13/2/2009 | 16/6/2026 | Buffer overflow in Becky! Internet Mail 2.48.02 and earlier allows remote attackers to execute arbitrary code via a mail message with a crafted return receipt request. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Infosoftglobal Fusion Charts | 5/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the dataURL parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Smartsitecms | 3/2/2009 | 16/6/2026 | SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the var parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Portalparts Forum Plugin | 25/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Geertsen Holdings INC Geecarts | 2/4/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 1.1% | — | Geertsen Holdings INC Geecarts | 2/4/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in GeeCarts allow remote attackers to execute arbitrary PHP code via a URL in the id parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Smartscript Domain Trader | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action. | |
| Modificada | Alta (10) | 5.5% | — | Tibco RtworksTibco Smartsockets RtserverTibco Enterprise Message Service | 16/1/2008 | 16/6/2026 | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers. | |
| Modificada | Alta (10) | 6.4% | — | Tibco Enterprise Message ServiceTibco RtworksTibco Smartsockets Rtserver | 16/1/2008 | 16/6/2026 | Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-length values that trigger the overflow. | |
| Modificada | Alta (10) | 5.5% | — | Tibco RtworksTibco Smartsockets RtserverTibco Enterprise Message Service | 16/1/2008 | 16/6/2026 | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets. | |
| Modificada | Alta (10) | 5.4% | — | Tibco Enterprise Message ServiceTibco RtworksTibco Smartsockets Rtserver | 16/1/2008 | 16/6/2026 | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted requests that control loop operations related to memory. | |
| Modificada | Media (6.8) | 31% | 💥 Exploit | Electronic Arts Snoopyctrl | 9/10/2007 | 16/6/2026 | Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Smartsitecms | 2/3/2007 | 16/6/2026 | admin.php in SmartSiteCMS 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the userName cookie. | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Mxbb Charts | 20/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | |
| Modificada | Media (5.1) | 4.2% | 💥 Exploit | Smartsitecms | 7/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a… | |
| Modificada | Alta (7.8) | 2.0% | — | Electronic Arts Nascar Racing | 6/7/2006 | 16/6/2026 | Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD asynchronous socket. | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | Smartsitecms | 22/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | |
| Modificada | Alta (7.8) | 0.39% | — | KDE Arts | 15/6/2006 | 16/6/2026 | artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges. | |
| Modificada | Media (5) | 2.6% | — | Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+6 | 2/5/2005 | 16/6/2026 | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data. | |
| Modificada | Alta (7.5) | 1.3% | — | Ecommerce-carts Ecommpro | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in login.asp for Ecommerce-Carts EcommPro 3.0 allows remote attackers to execute arbitrary SQL commands via the password field. | |
| Modificada | Media (5) | 4.3% | 💥 Exploit | Lucasarts Star Wars Jedi Knight Jedi Academy | 2/5/2005 | 16/6/2026 | Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname. |