Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2)0.19%—Volotat AnagnorisisAI24/9/202624/9/2026
A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filename Handler. Such manipulation of the argument file_path leads to cross site scripting. The attack can be launched remotely. The exploit is publicly…
AplazadaBaja (2.1)0.34%—Volotat AnagnorisisAI24/9/202624/9/2026
A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_streaming of the file page.html. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been publicly disclosed…
AplazadaMedia (5.5)0.38%—Volotat AnagnorisisAI24/9/202629/9/2026
A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missing authentication. It is possible to launch the attack remotely. The exploit has been made public and could be used. The…
AplazadaAlta (7.8)0.24%—Compugroup Medical CGM Isis MEDAI17/8/202631/8/2026
An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file.
ModificadaMedia (5.3)1.4%—Apache Isis19/10/202217/6/2026
When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made available with the ability to directly query the database. It was felt that it is safer to require the developer to explicitly enable this capability. As of 2.0.0-M8, this can now be done using the…
ModificadaMedia (6.1)1.3%—Apache Isis19/10/202217/6/2026
Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed. As of this release, the inputted strings…
ModificadaMedia (5)2.5%—Aspindir Kisisel Radyo Script2/11/201016/6/2026
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb.
ModificadaAlta (7.5)1.0%—Aspindir Kisisel Radyo Script2/11/201016/6/2026
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter.
ModificadaAlta (7.5)1.00%—Stormboards Aaronnemisis Stormboards26/12/200816/6/2026
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5)2.9%—Wwwisis16/10/200716/6/2026
Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot dot) in the IsisScript parameter to iah.
ModificadaMedia (4.3)1.5%—Wwwisis14/10/200716/6/2026
Cross-site scripting (XSS) vulnerability in wxis.exe in WWWISIS 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a call to the iah/iah.xis IsisScript code, possibly involving the lang or exprSearch parameter.
ModificadaMedia (6.8)4.7%—Lead Technologies Leadtools Raster Image SDKLead Technologies Leadtools Raster Isis Object1/6/200716/6/2026
Heap-based buffer overflow in a certain ActiveX control in LEADTOOLS LEAD Raster ISIS Object (LTRIS14e.DLL) 14.5.0.44 allows remote attackers to cause a denial of service (Internet Explorer crash) or execute arbitrary code via a long DriverName property, a different ActiveX control than CVE-2007-2827.
ModificadaAlta (9.3)6.4%—Lead Technologies Leadtools Isis Activex Control22/5/200716/6/2026
Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property.
ModificadaAlta (7.5)1.1%—Kisisel Site 2007 Kisisel Site Forum.asp7/2/200716/6/2026
SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
ModificadaAlta (10)5.4%—Wwwisis12/8/200216/6/2026
wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.