Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
238 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | R. Corson PHP Forge | 28/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine parameter. | |
| Modificada | Media (5.8) | 1.0% | — | Simian Systems INC Siteforge Collaborative Development Platform | 12/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index/siteforge-bugs-action/proj.siteforge in SiteForge Collaborative Development Platform 1.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) _status, (2) _extra1, (3) _extra2, or (4) _extra3 parameters. | |
| Modificada | Baja (2.6) | 1.2% | — | THE WAR Forge Warforge.news | 18/4/2006 | 16/6/2026 | SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie. | |
| Modificada | Baja (2.6) | 1.2% | — | THE WAR Forge Warforge.news | 18/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: portions of these details were obtained from third party sources… | |
| Modificada | Alta (10) | 9.7% | — | Net-snmpSourceforge Net-snmp | 31/12/2005 | 16/6/2026 | snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than… | |
| Modificada | Media (6.4) | 4.0% | 💥 Exploit | Gforge | 31/12/2005 | 16/6/2026 | viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter. | |
| Modificada | Media (4.3) | 2.7% | — | Gforge | 3/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to detail.php, (5) the text field on the search page, (6) group_id… | |
| Modificada | Media (5) | 1.3% | — | Gforge | 3/8/2005 | 16/6/2026 | The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb). | |
| Modificada | Media (5) | 1.7% | — | Gforge | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in GForge 3.3 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the (1) dir parameter to controller.php or (2) dir_name parameter to controlleroo.php. | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Arush DevastationDreamforge TNN Outdoors PRO HunterEpic Games Unreal EngineEpic Games Unreal Tournament+10 | 6/12/2004 | 16/6/2026 | The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b… | |
| Modificada | Media (4.3) | 0.84% | — | Sourceforge PHP Ticket | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Sourceforge Mymarket | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Sourceforge Newsdaemon | 3/5/2001 | 16/6/2026 | NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter. |