Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
311 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.6% | — | Adobe Coldfusion | 9/4/2008 | 16/6/2026 | Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these methods via Flex 2 remoting, a different vulnerability than CVE-2006-4725. | |
| Modificada | Alta (7.5) | 15% | — | Adobe Coldfusion | 12/3/2008 | 16/6/2026 | The administrator interface for Adobe ColdFusion 8 and ColdFusion MX7 does not log failed authentication attempts, which makes it easier for remote attackers to conduct brute force attacks without detection. | |
| Modificada | Media (4.3) | 2.1% | — | Adobe Coldfusion | 12/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 3.1% | — | Adobe Coldfusion | 12/3/2008 | 16/6/2026 | Adobe ColdFusion MX 7 and ColdFusion 8 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism for applications via unspecified vectors related to the setEncoding function. | |
| Modificada | Media (6.8) | 13% | — | Adobe Coldfusion | 15/11/2007 | 16/6/2026 | Adobe ColdFusion 8 and MX 7 allows remote attackers to hijack sessions via unspecified vectors that trigger establishment of a session to a ColdFusion application in which the (1) CFID or (2) CFTOKEN cookies have empty values, possibly due to a session fixation vulnerability. | |
| Modificada | Alta (7.2) | 0.73% | — | Adobe Coldfusion | 11/4/2007 | 16/6/2026 | Adobe ColdFusion MX 7 for Linux and Solaris uses insecure permissions for certain scripts and directories, which allows local users to execute arbitrary code or obtain sensitive information via the (1) CFMX7DreamWeaverExtensions.mxp, (2) CFReportBuilderInstaller.exe, (3) .com.zerog.registry.xml, (4) uninstall.lax, (5)… | |
| Modificada | Media (4.3) | 23% | — | Adobe ColdfusionAdobe Jrun | 16/3/2007 | 16/6/2026 | Unspecified vulnerability in the IIS connector in Adobe JRun 4.0 Updater 6, and ColdFusion MX 6.1 and 7.0 Enterprise, when using Microsoft IIS 6, allows remote attackers to cause a denial of service via unspecified vectors, involving the request of a file in the JRun web root. | |
| Modificada | Media (4.3) | 2.9% | — | Adobe ColdfusionAdobe Jrun | 14/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.3) | 2.7% | — | Adobe Coldfusion | 14/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not enabled, allows remote attackers to inject arbitrary HTML and web script via unknown vectors, possibly related to Linkdirect.cfm, Topnav.cfm, and Welcomedoc.cfm. | |
| Modificada | Media (4.3) | 8.6% | 💥 Exploit | Adobe Coldfusion | 7/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion web server allows remote attackers to inject arbitrary HTML or web script via the User-Agent HTTP header, which is not sanitized before being displayed in an error page. | |
| Modificada | Media (5) | 13% | — | Adobe ColdfusionAdobe Jrun | 31/12/2006 | 16/6/2026 | Adobe ColdFusion MX 7 through 7.0.2, and JRun 4, when run on Microsoft IIS, allows remote attackers to read arbitrary files, list directories, or read source code via a double URL-encoded NULL byte in a ColdFusion filename, such as a CFM file. | |
| Modificada | Media (5) | 2.3% | — | Adobe Coldfusion | 12/12/2006 | 16/6/2026 | Adobe ColdFusion MX7 allows remote attackers to obtain sensitive information via a URL request (1) for a non-existent (a) JWS, (b) CFM, (c) CFML, or (d) CFC file, which displays the installation path in the resulting error message; or (2) to /CFIDE/administrator/login.cfm without a host, which can reveal the server's… | |
| Modificada | Baja (2.6) | 2.4% | — | Adobe Coldfusion | 12/12/2006 | 16/6/2026 | Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonstrated using "%00script" in a tag. | |
| Modificada | Media (4.6) | 0.93% | — | Adobe Coldfusion | 10/10/2006 | 16/6/2026 | Unspecified vulnerability in a Verity third party library, as used on Adobe ColdFusion MX 7 through MX 7.0.2 and possibly other products, allows local users to execute arbitrary code via unknown attack vectors. | |
| Modificada | Media (4.6) | 0.65% | — | Adobe Coldfusion | 14/9/2006 | 16/6/2026 | Adobe ColdFusion MX 7 and 7.01 allows local users to bypass security restrictions and call components (CFC) within a sandbox from CFML templates that are located outside of the sandbox. | |
| Modificada | Media (5) | 2.5% | — | Adobe Coldfusion | 14/9/2006 | 16/6/2026 | Unspecified vulnerability in the ColdFusion Flash Remoting Gateway in Adobe ColdFusion MX 7 and 7.01 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors involving a crafted command. | |
| Modificada | Baja (2.6) | 1.8% | — | Adobe Coldfusion | 14/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page. | |
| Modificada | Alta (7.2) | 0.40% | — | Macromedia Coldfusion | 9/8/2006 | 16/6/2026 | The AdminAPI of ColdFusion MX 7 allows attackers to bypass authentication by using "programmatic access" to the adminAPI instead of the ColdFusion Administrator. | |
| Modificada | Media (5.8) | 1.3% | — | Macromedia Coldfusion | 15/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary web script or HTML via a "_required" field when the associated normal field is missing or empty, which is not sanitized before being presented in an error message. | |
| Modificada | Media (6.4) | 4.0% | 💥 Exploit | Application Dynamics Cartweaver Coldfusion | 26/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm. | |
| Modificada | Media (5) | 1.9% | — | Application Dynamics Cartweaver Coldfusion | 26/4/2006 | 16/6/2026 | Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allows remote attackers to obtain sensitive information via an invalid (1) secondary, (2) PageNum_Results, (3) category, or (4) keywords parameter in (a) Results.cfm; or an invalid (5) ProdID parameter in (b) Details.cfm; which reveal the path in various… | |
| Modificada | Alta (7.5) | 1.7% | — | Macromedia Coldfusion | 19/12/2005 | 16/6/2026 | ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability." | |
| Modificada | Alta (7.2) | 0.36% | — | Macromedia Coldfusion | 19/12/2005 | 16/6/2026 | Adobe (formerly Macromedia) ColdFusion MX 7.0 exposes the password hash of the Administrator in an API call, which allows local developers to obtain the hash and gain privileges. | |
| Modificada | Media (5) | 1.5% | — | Macromedia Coldfusion | 19/12/2005 | 16/6/2026 | Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 allows remote attackers to attach arbitrary files and send mail via a crafted Subject field, which is not properly handled by the CFMAIL tag in applications that use ColdFusion, aka "CFMAIL injection Vulnerability". | |
| Modificada | Baja (2.1) | 0.38% | — | Macromedia Coldfusion | 19/12/2005 | 16/6/2026 | Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an object despite the specified configuration. |