Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2627▼ 298 respecto a la semana anterior
Críticas / altas1348▲ 77 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.15%—Asprunner ProfessionalAI5/4/202624/7/2026
ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash.
AplazadaMedia (6.9)0.13%—Asprunner.netAI22/3/202617/6/2026
ASPRunner.NET 10.1 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the table name field. Attackers can input a buffer of 10000 characters in the table name parameter during database table creation to trigger an application crash.
ModificadaMedia (5)1.8%—Xlinesoft Asprunner31/12/200416/6/2026
ASPRunner 2.4 allows remote attackers to gain sensitive information via (1) hidden form fields or (2) error messages.
ModificadaMedia (5)8.8%—Xlinesoft Asprunner31/12/200416/6/2026
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) SearchFor parameter in [TABLE-NAME]_search.asp, (2) SQL parameter in [TABLE-NAME]_edit.asp, (3) SearchFor parameter in [TABLE]_list.asp, or (4) SQL parameter in export.asp.
ModificadaAlta (7.5)1.5%—Xlinesoft Asprunner31/12/200416/6/2026
SQL injection vulnerability in ASPRunner 2.4 allows remote attackers to execute arbitrary SQL statements.
ModificadaMedia (5)7.9%—Xlinesoft Asprunner31/12/200416/6/2026
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the database via a direct request to the database filename, which is predictable based on table and field names.