Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.5% | — | Libesedb Project Libesedb | 1/9/2018 | 17/6/2026 | The libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE: the vendor has disputed this as described in the GitHub issue comments | |
| Modificada | Media (6.5) | 1.5% | — | Libesedb Project Libesedb | 1/9/2018 | 17/6/2026 | The libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE: the vendor has disputed this as described in the GitHub issue comments | |
| Modificada | Media (6.5) | 1.5% | — | Libesedb Project Libesedb | 1/9/2018 | 17/6/2026 | The libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE: the vendor has disputed this as described in the GitHub issue comments | |
| Modificada | Media (5.4) | 0.74% | — | Nzedb | 5/6/2018 | 17/6/2026 | nZEDb v0.7.3.3 has XSS in the 404 error page. | |
| Modificada | Media (6.1) | 0.67% | — | Redbus Clone Script Project Redbus Clone Script | 5/4/2018 | 17/6/2026 | PHP Scripts Mall Redbus Clone Script 3.0.6 has XSS via the ter_from or tag parameter to results.php. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Hotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script | 13/12/2017 | 17/6/2026 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | |
| Modificada | Baja (2.6) | 0.75% | — | Zendesk Feedback TAB | 11/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Impliedbydesign Navigate | 27/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Navigate bar in the Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 4.8% | 💥 Exploit | Jesse Mcconnell RedbackApache Archiva | 6/12/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for… | |
| Modificada | Media (6.8) | 8.2% | 💥 Exploit | Ternaria COM Jfeedback | 19/4/2010 | 16/6/2026 | Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Memcachedb Memcached | 12/4/2010 | 16/6/2026 | memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 6.6% | — | Memcachedb Memcached | 10/8/2009 | 16/6/2026 | Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows. | |
| Modificada | Media (5) | 1.5% | — | Memcachedb Memcached | 30/4/2009 | 16/6/2026 | The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain potentially sensitive information by sending this command to the daemon's TCP port. | |
| Modificada | Media (5) | 2.3% | — | Memcachedb Memcached | 30/4/2009 | 16/6/2026 | The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the… | |
| Modificada | Alta (7.5) | 1.4% | — | Impliedbydesign IBD Micro CMS | 6/4/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) allow remote attackers to execute arbitrary SQL commands via (1) the administrators_username parameter (aka the Username field) or (2) the administrators_pass parameter (aka the Password field). | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Impliedbydesign Micro-cms | 30/3/2009 | 16/6/2026 | microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify… | |
| Modificada | Alta (7.1) | 32% | 💥 PoC | BSDBsdi BSD OSCisco IOSDragonflybsd+15 | 20/10/2008 | 16/6/2026 | The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as… | |
| Modificada | Alta (9.3) | 9.7% | 💥 Exploit | Jcomsoft AnigifSpeedbit Download Accelerator Plus | 15/8/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method. | |
| Modificada | Alta (7.5) | 1.8% | — | Speedbit Video Accelerator | 1/8/2008 | 16/6/2026 | SpeedBit Video Acceleration before 2.2.1.8 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |
| Modificada | Alta (7.5) | 1.8% | — | Speedbit Download Accelerator Plus | 1/8/2008 | 16/6/2026 | SpeedBit Download Accelerator Plus (DAP) before 8.6.3.9 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | 1scripts Codedb | 16/7/2008 | 16/6/2026 | Directory traversal vulnerability in list.php in 1Scripts CodeDB 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | |
| Modificada | Alta (9.3) | 7.4% | 💥 Exploit | Speedbit Download Accelerator Plus | 15/7/2008 | 16/6/2026 | Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allows user-assisted remote attackers to execute arbitrary code via an M3U (.m3u) file containing a long MP3 URL. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Cmsnx Feedback AND Rating Script | 16/5/2008 | 16/6/2026 | SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary SQL commands via the listingid parameter. | |
| Modificada | Media (6.4) | 4.9% | 💥 Exploit | Feedburner Feedsmith | 5/10/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to FeedBurner_FeedSmith_Plugin.php, as demonstrated by the (1) feedburner_url… | |
| Modificada | Media (6.5) | 5.1% | 💥 Exploit | Enterprisedb Postgres Advanced Server | 31/8/2007 | 16/6/2026 | EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg_ function, as… |