Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.2%💥 ExploitOpen Source Technology Group Sourceforge27/10/200616/6/2026
PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter.
ModificadaMedia (5.1)10%💥 ExploitClarolineDokeos Open Source Learning AND Knowledge Management Tool19/9/200616/6/2026
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.
ModificadaMedia (4.3)1.8%—JAM Warehouse Knowledgetree Open Source7/6/200616/6/2026
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS.
ModificadaMedia (5.1)4.1%💥 ExploitDokeos Open Source Learning AND Knowledge Management Tool10/5/200616/6/2026
PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.
ModificadaAlta (7.5)1.4%—Digger Solutions Intranet Open SourceAI31/12/200516/6/2026
SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via the project_id parameter.
ModificadaAlta (9.4)1.8%—Mambo Open Source 4.511/12/200516/6/2026
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character.
ModificadaBaja (2.1)0.36%—F2C Open Source Project F2C Translator2/5/200516/6/2026
The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
ModificadaBaja (2.1)0.39%—Netatalk Open Source Apple File Share Protocol SuiteMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core9/2/200516/6/2026
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
ModificadaMedia (4.3)1.4%—Open Source Development Network Slashcode31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl.
ModificadaMedia (6.8)4.2%💥 ExploitMambo Open Source31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.
ModificadaMedia (4.3)1.8%💥 ExploitMambo Open Source18/9/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.
ModificadaAlta (7.5)1.2%💥 ExploitMambo Open Source 4.516/3/200416/6/2026
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)2.0%💥 ExploitMambo Open Source16/3/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.
ModificadaMedia (6.8)1.3%—Open Source Development Network Slashcode31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragraph <P> tag.
ModificadaAlta (7.2)0.78%—Open Source Development Network Slashcode31/12/200216/6/2026
Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts.
ModificadaMedia (6.4)1.2%—Open Source Internet Solutions31/12/200216/6/2026
Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors.
ModificadaBaja (2.6)1.3%—Open Source Development Network Slashcode31/5/200216/6/2026
Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.
ModificadaMedia (4.6)0.35%—Open Source Development Network Slashcode31/12/200116/6/2026
Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack.
ModificadaAlta (7.5)2.2%—Open Source Development Network Slashcode11/12/200016/6/2026
The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly execute arbitrary commands.