Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.67% | — | Bbpress Move Topics Project Bbpress Move Topics | 27/8/2019 | 17/6/2026 | The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 2.1% | — | Bbpress Move Topics Project Bbpress Move Topics | 27/8/2019 | 17/6/2026 | The bbp-move-topics plugin before 1.1.6 for WordPress has code injection. | |
| Modificada | Alta (7.8) | 2.8% | — | Schneider-electric ATV Lift DTMSchneider-electric Atv12 DTMSchneider-electric Atv212 DTMSchneider-electric Atv31 DTM+9 | 9/3/2018 | 17/6/2026 | A DLL hijacking vulnerability exists in Schneider Electric's SoMove Software and associated DTM software components in all versions prior to 2.6.2 which could allow an attacker to execute arbitrary code. | |
| Modificada | Media (6.1) | 1.5% | — | Ipswitch Moveit | 2/2/2018 | 17/6/2026 | Ipswitch MoveIt v8.1 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability, as demonstrated by human.aspx. Attackers can leverage this vulnerability to send malicious messages to other users in order to steal session cookies and launch client-side attacks. | |
| Modificada | Alta (7) | 0.38% | — | Norton Remove & Reinstall | 28/9/2017 | 17/6/2026 | Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to… | |
| Modificada | Alta (7.8) | 1.1% | — | Sony NFC Port Software Remover | 2/8/2017 | 17/6/2026 | Untrusted search path vulnerability in NFC Port Software remover Ver.1.3.0.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Crítica (9.8) | 2.0% | — | Ipswitch Moveit DMZIpswitch Moveit Transfer 2017 | 18/5/2017 | 17/6/2026 | Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20. | |
| Modificada | Media (5.4) | 1.8% | — | Ipswitch Moveit DMZ | 15/4/2016 | 17/6/2026 | Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files. | |
| Modificada | Media (5.3) | 2.1% | — | Ipswitch Moveit DMZ | 10/2/2016 | 17/6/2026 | Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx. | |
| Modificada | Media (6.1) | 1.4% | — | Ipswitch Moveit Mobile | 10/2/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/. | |
| Modificada | Alta (8.8) | 0.91% | — | Ipswitch Moveit Mobile | 10/2/2016 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (4.3) | 3.0% | — | Ipswitch Moveit DMZ | 10/2/2016 | 17/6/2026 | The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll. | |
| Modificada | Media (6.5) | 3.1% | — | Ipswitch Moveit DMZIpswitch Moveit Mobile | 10/2/2016 | 17/6/2026 | The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx. | |
| Modificada | Baja (3.5) | 0.94% | — | Mover Project Mover | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Mover module 6.x-1.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 5.6% | — | Schneider-electric SomachineSchneider-electric SomoveSchneider-electric Somove LiteSchneider-electric Unity PRO | 1/2/2015 | 17/6/2026 | Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB… | |
| Modificada | Alta (9.3) | 22% | 💥 Exploit | Schneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+9 | 1/4/2014 | 16/6/2026 | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header. | |
| Modificada | Alta (10) | 1.7% | — | Movesti Acontact | 14/3/2012 | 16/6/2026 | Unspecified vulnerability in the AContact (com.movester.quickcontact) application 1.8.2 for Android has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Accimoveis Descargarvista ACC Imoveis | 17/11/2010 | 16/6/2026 | SQL injection vulnerability in imoveis.php in DescargarVista ACC IMoveis 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.9) | 0.41% | — | Bitmover Lmbench | 6/11/2008 | 16/6/2026 | The (1) rccs and (2) STUFF scripts in lmbench 3.0-a7 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/sdiff.##### temporary file. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | Move Networks INC Move Media PlayerMove Networks INC Qunatum Streaming Player | 27/2/2008 | 16/6/2026 | Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.7.6.7 and qsp2ie07074039.dll 7.7.4.39 in Move Media Player allows remote attackers to execute arbitrary code via a long argument to the UploadLogs method, a different… | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Move Networks INC Move Media Player | 29/1/2008 | 16/6/2026 | Stack-based buffer overflow in the QMPUpgrade.Upgrade.1 ActiveX control in QMPUpgrade.dll 1.0.0.1 in Move Networks Upgrade Manager allows remote attackers to execute arbitrary code via a long first argument to the Upgrade method. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 10% | 💥 Exploit | Move Networks INC Move Media Player | 5/9/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie07051001.dll 1.0.0.1 in Move Media Player allow remote attackers to execute arbitrary code via a long string to the (1) Play and (2) Buzzer methods. | |
| Modificada | Alta (7.5) | 3.2% | — | Mitch Murray Eremove | 10/8/2006 | 16/6/2026 | Buffer overflow in the preview_create function in gui.cpp in Mitch Murray Eremove 1.4 allows remote attackers to cause a denial of service (application crash), and possibly execute arbitrary code, via a large email attachment. | |
| Modificada | Alta (9.3) | 4.7% | — | Sunncomm Mediamax Axwebremovectrl | 19/11/2005 | 16/6/2026 | The AxWebRemoveCtrl ActiveX control for uninstalling the SunnComm MediaMax DRM allows remote attackers to download and execute arbitrary code, a similar vulnerability to CVE-2005-3650. |