Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Open Source Technology Group Sourceforge | 27/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter. | |
| Modificada | Media (5.1) | 10% | 💥 Exploit | ClarolineDokeos Open Source Learning AND Knowledge Management Tool | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter. | |
| Modificada | Media (4.3) | 1.8% | — | JAM Warehouse Knowledgetree Open Source | 7/6/2006 | 16/6/2026 | view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS. | |
| Modificada | Media (5.1) | 4.1% | 💥 Exploit | Dokeos Open Source Learning AND Knowledge Management Tool | 10/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Digger Solutions Intranet Open SourceAI | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. | |
| Modificada | Alta (9.4) | 1.8% | — | Mambo Open Source 4.5 | 11/12/2005 | 16/6/2026 | Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character. | |
| Modificada | Baja (2.1) | 0.36% | — | F2C Open Source Project F2C Translator | 2/5/2005 | 16/6/2026 | The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 0.39% | — | Netatalk Open Source Apple File Share Protocol SuiteMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core | 9/2/2005 | 16/6/2026 | The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Media (4.3) | 1.4% | — | Open Source Development Network Slashcode | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl. | |
| Modificada | Media (6.8) | 4.2% | 💥 Exploit | Mambo Open Source | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Mambo Open Source | 18/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mambo Open Source 4.5 | 16/3/2004 | 16/6/2026 | SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Mambo Open Source | 16/3/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters. | |
| Modificada | Media (6.8) | 1.3% | — | Open Source Development Network Slashcode | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragraph <P> tag. | |
| Modificada | Alta (7.2) | 0.78% | — | Open Source Development Network Slashcode | 31/12/2002 | 16/6/2026 | Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts. | |
| Modificada | Media (6.4) | 1.2% | — | Open Source Internet Solutions | 31/12/2002 | 16/6/2026 | Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors. | |
| Modificada | Baja (2.6) | 1.3% | — | Open Source Development Network Slashcode | 31/5/2002 | 16/6/2026 | Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field. | |
| Modificada | Media (4.6) | 0.35% | — | Open Source Development Network Slashcode | 31/12/2001 | 16/6/2026 | Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack. | |
| Modificada | Alta (7.5) | 2.2% | — | Open Source Development Network Slashcode | 11/12/2000 | 16/6/2026 | The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly execute arbitrary commands. |