Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Paolo GeodirectoryAI | 1/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157. | |
| Aplazada | Media (4.3) | 0.15% | — | Paolo GeodirectoryAI | 23/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paolo GeoDirectory geodirectory allows Cross Site Request Forgery.This issue affects GeoDirectory: from n/a through <= 2.8.149. | |
| Analizada | Media (6.5) | 0.24% | — | Xiaoliuchu Pss.sale.com | 9/1/2026 | 17/6/2026 | SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint. | |
| Aplazada | Alta (8.4) | 0.53% | — | AOLAI | 21/8/2025 | 16/6/2026 | AOL versions up to and including 9.5 includes an ActiveX control (Phobos.dll) that exposes a method called Import() via the Phobos.Playlist COM object. This method is vulnerable to a stack-based buffer overflow when provided with an excessively long string argument. Exploitation allows remote attackers to execute… | |
| Aplazada | Alta (8.4) | 0.51% | — | AOL DesktopAI | 20/8/2025 | 16/6/2026 | AOL Desktop 9.6 contains a buffer overflow vulnerability in its Tool\rich.rct component when parsing .rtx files. By embedding an overly long string in a hyperlink tag, an attacker can trigger a stack-based buffer overflow due to the use of unsafe strcpy operations. This allows remote attackers to execute arbitrary… | |
| Aplazada | Media (6.5) | 0.26% | — | Paolo Melchiorre Send E-mailAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo Melchiorre Send E-mail send-e-mail allows Stored XSS.This issue affects Send E-mail: from n/a through <= 1.3. | |
| Aplazada | Media (6.9) | 0.53% | — | Guangdong Baolun Electronics IP Network Broadcasting Service PlatformAI | 14/6/2024 | 17/6/2026 | A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been classified as critical. Affected is an unknown function of the file /api/v2/maps. The manipulation of the argument orderColumn leads to sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Media (5.3) | 0.73% | — | AOL AIM TritonAI | 10/3/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in AOL AIM Triton 1.0.4. It has been declared as problematic. This vulnerability affects unknown code of the component Invite Handler. The manipulation of the argument CSeq leads to denial of service. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 3.1% | — | Gmaolinx Linx Sphere | 12/12/2022 | 17/6/2026 | A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files. | |
| Modificada | Alta (7.5) | 0.44% | — | Philips Taolight Smart Wi-fi WIZ Connected LED Bulb 9290022656 Firmware | 14/11/2019 | 17/6/2026 | On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users control the bulb's operation. Anyone can turn the bulb on or off, or change its color or brightness remotely. There is no authentication or encryption to use the control API. The only requirement is… | |
| Modificada | Alta (7.5) | 2.0% | — | 11xiaoli Project 11xiaoli | 7/6/2018 | 17/6/2026 | 11xiaoli is a simple file server. 11xiaoli is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Caolilinode Project Caolilinode | 7/6/2018 | 17/6/2026 | caolilinode is a simple file server. caolilinode is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Media (5.4) | 0.27% | — | AOL Dailyfinance - Stocks & News | 9/9/2014 | 17/6/2026 | The DailyFinance - Stocks & News (aka com.aol.mobile.dailyFinance) application 2.0.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.8) | 0.57% | — | AOL AIM | 4/11/2012 | 16/6/2026 | AOL Instant Messenger (AIM) 1.0.1.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (5) | 8.9% | — | Aolserver | 13/1/2010 | 16/6/2026 | AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Alta (8.8) | 8.9% | — | AOL Superbuddy Activex Control | 9/10/2009 | 16/6/2026 | Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method. | |
| Modificada | Media (6.8) | 2.6% | — | Zenas Paolink | 25/9/2009 | 16/6/2026 | login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | |
| Modificada | Media (6.8) | 2.6% | — | Zenas Paoliber | 25/9/2009 | 16/6/2026 | login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | |
| Modificada | Media (4.3) | 1.5% | — | Zenas Paolink | 23/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Alta (7.5) | 2.7% | — | Paolo Palmonari Photoracer Plugin FOR Wordpress | 19/6/2009 | 16/6/2026 | SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 4.5% | — | AOL YGP Piceditor Activex Control | 4/2/2008 | 16/6/2026 | Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5)… | |
| Modificada | Alta (9.3) | 24% | — | AolmediaplaybackcontrolMicrosoft Ampx | 9/1/2008 | 16/6/2026 | Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might allow remote attackers to execute arbitrary code via the AppendFileToPlayList method. | |
| Modificada | Alta (9.3) | 13% | — | AOL Radio | 14/11/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote attackers to execute arbitrary code via long arguments to unspecified methods. | |
| Modificada | Media (6.8) | 1.9% | — | AOL Instant Messenger | 27/9/2007 | 16/6/2026 | The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.5.3.12 and earlier allows remote attackers to execute arbitrary code via unspecified web script or HTML in an instant message, related to AIM's filtering of "specific tags and attributes" and the lack of Local Machine Zone lockdown. NOTE:… | |
| Modificada | Media (5.8) | 2.8% | — | AOL AIM LiteAOL AIM PROAOL Instant Messenger | 14/9/2007 | 16/6/2026 | The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute… |