Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.21% | — | KazaarAI | 1/10/2025 | 17/6/2026 | Kazaar 1.25.12 allows /api/v1/org-id/orders/order-id/documents calls with a modified order-id. | |
| Aplazada | Media (5.3) | 0.32% | — | KazaarAI | 1/10/2025 | 17/6/2026 | Kazaar 1.25.12 allows a JWT with none in the alg field. | |
| Modificada | Media (4.3) | 1.5% | — | Mykazaam Notes Management System | 1/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to inject arbitrary web script or HTML via vectors involving the "Enter Reference Number Below" text box. | |
| Modificada | Alta (7.5) | 1.0% | — | Mykazaam Notes Management System | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in notes.php in My Kazaam Notes Management System allows remote attackers to execute arbitrary SQL commands via vectors involving the "Enter Reference Number Below" text box. | |
| Modificada | Alta (7.5) | 0.99% | — | Mykazaam Address & Contact Organizer | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in address_book/contacts.php in My Kazaam Address & Contact Organizer allows remote attackers to execute arbitrary SQL commands via the var1 parameter. | |
| Modificada | Media (6.8) | 30% | — | Altnet Download ManagerGroksterKazaa Media Desktop | 5/10/2007 | 16/6/2026 | Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 4.2% | — | Altnet Download ManagerGroksterKazaa Media Desktop | 31/12/2004 | 16/6/2026 | Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath parameter. | |
| Modificada | Alta (7.5) | 3.5% | — | Kazaa Media Desktop | 31/12/2003 | 16/6/2026 | KaZaA Media Desktop (KMD) 2.0 launches advertisements in the Internet Explorer (IE) local security zone, which could allow remote attackers to view local files and possibly execute arbitrary code. | |
| Modificada | Alta (9) | 4.0% | — | Kazaa Media Desktop | 31/12/2003 | 16/6/2026 | Buffer overflow in KaZaA Media Desktop 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a response to the ad server. | |
| Modificada | Alta (7.5) | 4.1% | — | Sharman Networks Kazaa | 2/7/2003 | 16/6/2026 | Buffer overflow in FastTrack (FT) network code, as used in Kazaa 2.0.2 and possibly other versions and products, allows remote attackers to execute arbitrary code via a packet containing a large list of supernodes, aka "Packet 0' death." | |
| Modificada | Alta (7.8) | 3.2% | — | Kazaa Media Desktop | 31/12/2002 | 16/6/2026 | Sharman Networks KaZaA Media Desktop 1.7.1 allows remote attackers to cause a denial of service (CPU consumption) by sending several large messages. | |
| Modificada | Alta (7.5) | 1.8% | — | Fasttrack KazaaGroksterMusic City Networks Morpheus | 25/6/2002 | 16/6/2026 | fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header. | |
| Modificada | Media (5) | 1.7% | — | Fasttrack KazaaGroksterMusic City Networks Morpheus | 25/6/2002 | 16/6/2026 | fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. |