Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 8.2% | 💥 Exploit | Oracle Glassfish Server | 6/5/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBeans/customMBeans.jsf, (4)… | |
| Modificada | Media (4.3) | 5.4% | 💥 Exploit | SUN Java System Application ServerOracle Glassfish Server | 28/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Gonafish Linkscaffepro | 24/9/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Oracle Glassfish ServerSUN Java System Application Server | 18/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to inject arbitrary web script or HTML via the (1) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (2)… | |
| Modificada | Alta (9.3) | 6.5% | — | Xine-libXiph SpeexXiph Libfishsound | 8/4/2008 | 16/6/2026 | Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annodex Plugins for Firefox, xine-lib before 1.1.12, and many other products, allows remote attackers to execute arbitrary code via a header structure containing a negative… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Fishcart | 9/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in fc_functions/fc_example.php in FishCart 3.2 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the docroot parameter. | |
| Modificada | Alta (10) | 9.1% | 💥 Exploit | Fish | 10/3/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote attackers to execute arbitrary code via long strings. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Cuttlefish Leicestershire Communityportals | 7/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Fishyshoop | 27/12/2006 | 16/6/2026 | pages/register/register.php in Fishyshoop 0.930 beta allows remote attackers to create arbitrary administrative users by setting the is_admin HTTP POST parameter to 1. | |
| Modificada | Media (6.8) | 1.9% | — | Cuttlefish Multimedia Ltd. Leicestershire Communityportals | 13/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/import-archive.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Gonafish.com Linkscaffe | 31/8/2006 | 16/6/2026 | Gonafish.com LinksCaffe 2.0 and 3.0 do not properly restrict access to administrator functions, which allows remote attackers to gain full administration rights via a direct request to Admin/admin1953.php. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Mambo Mambelfish Component | 21/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (5.1) | 1.1% | — | Gonafish Linkscaffe | 31/7/2006 | 16/6/2026 | SQL injection vulnerability in links.php in Gonafish LinksCaffe 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Gonafish Linkscaffe | 27/7/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) offset and (2) limit parameters, (3) newdays parameter in a new action, and the (4) link_id parameter in a deadlink action. NOTE: this issue can also be used for path… | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Gonafish Linkscaffe | 27/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3) tableborder, (4) menucolor, (5) textcolor, and (6) bodycolor… | |
| Modificada | Baja (1.2) | 0.39% | — | Solar Designer Crypt Blowfish | 8/2/2006 | 16/6/2026 | The crypt_gensalt functions for BSDI-style extended DES-based and FreeBSD-sytle MD5-based password hashes in crypt_blowfish 0.4.7 and earlier do not evenly and randomly distribute salts, which makes it easier for attackers to guess passwords from a stolen password file due to the increased number of collisions. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Fishnet Fishcart | 11/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are forced SQL errors. The original researcher is known to be… | |
| Modificada | Media (5) | 4.0% | 💥 Exploit | Fishnet Fishcart | 11/5/2005 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendor was not able to reproduce some of the reported vectors but… | |
| Modificada | Alta (7.5) | 1.3% | — | Fishnet Fishcart | 17/2/2004 | 16/6/2026 | Integer overflow in the rnd arithmetic rounding function for various versions of FishCart before 3.1 allows remote attackers to "cause negative totals" via an order with a large quantity. | |
| Modificada | Alta (7.5) | 0.71% | — | Starfish Truesync Desktop | 31/8/2001 | 16/6/2026 | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges. | |
| Modificada | Media (5) | 1.1% | — | Starfish Truesync Desktop | 31/8/2001 | 16/6/2026 | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application. | |
| Modificada | Media (5) | 1.1% | — | Starfish Truesync Desktop | 31/8/2001 | 16/6/2026 | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack. |