Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.34%—IBM Advanced Settings UtilityIBM Bootable Media Creator19/12/201216/6/2026
IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file.
ModificadaMedia (6.9)1.0%💥 ExploitRoxio Easy Media Creator7/9/201216/6/2026
Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a Trojan horse homeutils9.dll file in the current working directory, as demonstrated by a directory that contains a .roxio, .c2d, or .gi file. NOTE: some of these details are obtained from third party…
ModificadaMedia (4.3)1.1%—Netcreators Irfaq14/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the "return url parameter."
ModificadaMedia (5.8)1.1%—Netcreators Irfaq14/2/201216/6/2026
Open redirect vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL, probably in the "return url parameter."
ModificadaBaja (2.1)0.36%—Evan Dandrea Usb-creator16/5/201116/6/2026
usb-creator-helper in usb-creator before 0.2.28.3 does not enforce intended PolicyKit restrictions, which allows local users to perform arbitrary unmount operations via the UnmountFile method in a dbus-send command.
ModificadaMedia (6.9)0.35%—Nokia QT Creator4/10/201016/6/2026
Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
ModificadaMedia (4.3)6.4%💥 ExploitJE Form Creator30/3/201016/6/2026
Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE…
ModificadaMedia (5)1.6%—Comscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
ModificadaAlta (7.5)3.0%💥 ExploitComscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php.
ModificadaMedia (4.3)1.4%💥 ExploitComscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php.
ModificadaMedia (6.8)1.1%💥 ExploitWscreator17/12/200916/6/2026
SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parameter.
ModificadaAlta (9.3)6.7%—Roxio CreatorRoxio Easy Media Creator3/12/200916/6/2026
Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimensions.
ModificadaMedia (6.8)0.85%💥 ExploitCpecreator CP Creator23/9/200916/6/2026
SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticket action.
ModificadaAlta (7.5)3.5%💥 ExploitCreative Mind Creator CMS19/8/200916/6/2026
Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)2.3%💥 ExploitComscripts WEB Server Creator WEB Portal30/3/200916/6/2026
PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)3.6%💥 ExploitTizag Countdown Creator20/3/200916/6/2026
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from…
ModificadaAlta (7.5)1.1%💥 ExploitCreative Mind Creator CMS1/10/200816/6/2026
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter.
ModificadaMedia (4.3)1.5%💥 ExploitM2scripts MY Space Scripts Poll Creator27/11/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in M2Scripts MySpace Scripts Poll Creator allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) intro, and (3) question parameters, and (4) unspecified answer parameters, in a create_new action. NOTE: some of these details…
ModificadaAlta (7.5)1.1%—Advanced Website Creator30/3/200716/6/2026
Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string.
ModificadaMedia (6.8)2.7%💥 ExploitWebcreator14/3/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files.
ModificadaAlta (10)8.8%💥 ExploitPhppc PHP Poll Creator7/3/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and version than CVE-2005-1755.
ModificadaAlta (7.5)2.1%💥 ExploitPHP Poll Creator7/3/200716/6/2026
PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a different vector and version than CVE-2005-1755. NOTE: the provenance of this information is unknown; the details are…
ModificadaMedia (6.8)1.5%—Xenis.creator CMS8/11/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in xenis.creator CMS allow remote attackers to inject arbitrary web script or HTML via the (1) contid or (2) search parameters.
ModificadaAlta (7.5)1.2%—Xenis.creator CMS8/11/200616/6/2026
SQL injection vulnerability in default.asp in Xenis.creator CMS allows remote attackers to execute arbitrary SQL commands via the contid parameter.
ModificadaBaja (2.6)0.85%—Xenis.creator CMS8/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in default.asp in xenis.creator CMS allows remote attackers to inject arbitrary web script or HTML via the nav parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.