Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+10 | 5/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hitachi Web Server 01-00 through 03-10, as used by certain Cosminexus products, allows remote attackers to inject arbitrary web script or HTML via unspecified HTTP requests that trigger creation of a server-status page. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Jobsiteprofessional Jobsite Professional | 1/11/2007 | 16/6/2026 | SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 2.2% | — | Hitachi Ucosminexus Application Server EnterpriseHitachi Ucosminexus Application Server StandardHitachi Ucosminexus ClientHitachi Ucosminexus Developer Professional+4 | 9/10/2007 | 16/6/2026 | The Java Secure Socket Extension (JSSE) in the Hitachi Cosminexus Developer's Kit for Java in various Hitachi Cosminexus 7.5 products before 07-50-01, when using JSSE for SSL/TLS support, allows remote attackers to cause a denial of service via certain SSL/TLS handshake requests. NOTE: this may be the same as… | |
| Modificada | Media (5) | 1.8% | — | Cgi-rescue Shopping Basket Professional | 4/9/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi. | |
| Modificada | Media (4.4) | 0.28% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+3 | 28/8/2007 | 16/6/2026 | Cosminexus Manager in Cosminexus Application Server 06-50 and later might assign the wrong user's group permissions to logical J2EE server processes, which allows local users to gain privileges. | |
| Modificada | Media (4.6) | 0.31% | — | Hitachi Cosminexus Application Server EnterpriseHitachi Cosminexus Application Server StandardHitachi Electronic Form Workflow - Standard SETHitachi Electronic Form Workflow -professional Library SET+3 | 28/8/2007 | 16/6/2026 | Cosminexus Manager in Cosminexus Application Server 07-00 and later might assign the wrong user's group permissions to logical user server processes, which allows local users to gain privileges. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Aleadsoft.com Search Engine Builder Professional | 22/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.html in Search Engine Builder allows remote attackers to inject arbitrary web script or HTML via the searWords parameter. | |
| Modificada | Alta (7.8) | 3.2% | — | AmavisAvast AntivirusAvast Antivirus HomeAvast Antivirus Professional+9 | 9/5/2007 | 16/6/2026 | unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. | |
| Modificada | Alta (7.8) | 2.5% | — | Raiden Professional Servers Raidenftpd | 24/4/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in IXceedCompression in XceddZipLib (RaidenFTPD.dll) in RaidenFTPD 2.4 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving the (1) CalculateCrc, (2) Compress, and (3) Uncompress functions, which result in a NULL pointer dereference. | |
| Modificada | Alta (9) | 12% | 💥 Exploit | Mailenable EnterpriseMailenable Professional | 7/3/2007 | 16/6/2026 | Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users to execute arbitrary code via a long argument to the APPEND command. NOTE: this is probably different than CVE-2006-6423. | |
| Modificada | Media (4.3) | 1.3% | — | Professional Home Page Tools Login Script | 2/3/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Professional Home Page Tools Login Script, as of July 2006, allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) vorname, and (3) nachname parameters in the register script. NOTE: some details have been obtained from third party… | |
| Modificada | Media (4.3) | 3.1% | — | Mailenable Professional | 15/2/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/. | |
| Modificada | Media (5.1) | 1.6% | — | Mailenable Professional | 15/2/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag. | |
| Modificada | Alta (7.5) | 1.4% | — | Cgi-rescue Shopping Basket Professional | 30/1/2007 | 16/6/2026 | CGI-Rescue Shopping Basket Professional 7.50 and earlier allows remote attackers to inject arbitrary operating system commands via unspecified vectors. | |
| Modificada | Media (4) | 1.0% | — | Mailenable Professional | 29/1/2007 | 16/6/2026 | MailEnable Professional before 1.78 provides a cleartext user password when an administrator edits the user's settings, which allows remote authenticated administrators to obtain sensitive information by viewing the HTML source. | |
| Modificada | Media (6.8) | 1.2% | — | Hitachi Cosminexus Application ServerHitachi Cosminexus Application Server Version 5Hitachi Cosminexus Developer Light Version 6Hitachi Cosminexus Developer Professional Version 6+15 | 26/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in multiple Hitachi Web Server, uCosminexus, and Cosminexus products before 20070124 allow remote attackers to inject arbitrary web script or HTML via (1) HTTP Expect headers or (2) image maps. | |
| Modificada | Alta (10) | 5.9% | — | Mailenable EnterpriseMailenable ProfessionalMailenable Standard | 19/12/2006 | 16/6/2026 | Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41, and 2.35 and earlier before ME-10026 allows remote attackers to execute arbitrary code via a long argument to the PASS command. | |
| Modificada | Media (5) | 3.0% | — | Mailenable EnterpriseMailenable Professional | 12/12/2006 | 16/6/2026 | The IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.34, Professional Edition 1.6 through 1.83, and Enterprise Edition 1.1 through 1.40 allows remote attackers to cause a denial of service (crash) via unspecified vectors that trigger a null pointer dereference, as addressed by the ME-10023… | |
| Modificada | Alta (10) | 71% | 💥 Exploit | Mailenable EnterpriseMailenable Professional | 12/12/2006 | 16/6/2026 | Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1.1 through 1.41 allows remote attackers to execute arbitrary code via a pre-authentication command followed by a crafted parameter and a… | |
| Modificada | Media (6.8) | 0.98% | 💥 Exploit | Iware Professional | 10/12/2006 | 16/6/2026 | SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the D parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.5) | 3.3% | — | Mailenable EnterpriseMailenable Professional | 5/12/2006 | 16/6/2026 | Multiple stack-based buffer overflows in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.82 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.30 and 2.0 through 2.33 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a long… | |
| Modificada | Alta (7.5) | 1.6% | — | Mailenable Netwebadmin EnterpriseMailenable Netwebadmin Professional | 3/12/2006 | 16/6/2026 | webadmin in MailEnable NetWebAdmin Professional 2.32 and Enterprise 2.32 allows remote attackers to authenticate using an empty password. | |
| Modificada | Alta (9.3) | 7.1% | 💥 Exploit | Mailenable EnterpriseMailenable Professional | 10/10/2006 | 16/6/2026 | The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vectors involving crafted base64 encoded NTLM Type 3 messages, or (2) cause a denial of service via crafted base64 encoded NTLM Type 1 messages, which trigger a buffer… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Klinza Professional CMS | 10/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in funzioni/lib/show_hlp.php in klinza professional cms 5.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appl[APPL] parameter. | |
| Modificada | Alta (9.3) | 5.4% | — | Mailenable EnterpriseMailenable Professional | 10/10/2006 | 16/6/2026 | Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the signature field of NTLM Type 1 messages". |