Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▲ 26 respecto a la semana anterior
Críticas / altas1468▲ 333 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.78% | — | Erlang OTPAIErlang MegacoAI | 27/7/2026 | 8/9/2026 | Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message containing an oversized property parm name.… | |
| Analizada | Crítica (9.8) | 1.1% | — | Megacord Megabot | 20/8/2024 | 17/6/2026 | MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the `expression` parameter when using `/math` in any… | |
| Modificada | Media (4.3) | 1.2% | — | Globalmegacorp Phpchain | 14/5/2007 | 16/6/2026 | PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations. | |
| Modificada | Media (4.3) | 1.9% | — | Globalmegacorp Phpchain | 14/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHPChain 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the catid parameter to (1) settings.php or (2) cat.php. NOTE: certain parameter values also trigger path disclosure. | |
| Modificada | Media (6.8) | 1.4% | — | Globalmegacorp Dvddb | 4/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DVDdb 0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the movieid parameter to loan.php or (2) the s parameter to listmovies.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Globalmegacorp Dvddb | 6/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the config parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Globalmegacorp Dvddb | 6/2/2007 | 16/6/2026 | SQL injection vulnerability in inc/common.php in GlobalMegaCorp dvddb 0.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: this issue has been disputed by a reliable third party, who states that inc/common.php only contains function definitions |