Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 4.8% | 💥 Exploit | Harmistechnology COM Jesectionfinder | 12/7/2010 | 16/6/2026 | Directory traversal vulnerability in the JExtensions JE Section/Property Finder (jesectionfinder) component for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the view parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | — | TW Productfinder | 2/12/2009 | 16/6/2026 | SQL injection vulnerability in the TW Productfinder (tw_productfinder) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Realtysoft PG Roomate Finder Solution | 14/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php. | |
| Modificada | Media (4.3) | 1.2% | — | Infrae SilvaInfrae Silva Find | 31/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Silva Find extension 1.1.5 and earlier in Silva 1.x before 1.6.3.2, Silva 2.0 before 2.0.12.2, and Silva 2.1 before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the fulltext parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Pilot Group PG Real Roommate Finder Solution | 2/12/2008 | 16/6/2026 | SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | CTW Design Findnix | 14/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in FindNix allows remote attackers to include the contents of arbitrary URLs and conduct cross-site scripting (XSS) attacks via a URL in the page parameter. | |
| Modificada | Media (6) | 2.2% | — | GNU Findutils | 4/6/2007 | 16/6/2026 | Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Xoops Friendfinder Module | 3/4/2007 | 16/6/2026 | SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Interspire Fastfind | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Multitech Routefinder 550 VPN | 18/3/2003 | 16/6/2026 | The web interface for SOHO Routefinder 550 firmware 4.63 and earlier, and possibly later versions, has a default "admin" account with a blank password, which could allow attackers on the LAN side to conduct unauthorized activities. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Multitech Routefinder 550 VPN | 18/3/2003 | 16/6/2026 | Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a denial of service (reboot) and execute arbitrary code via a long GET /OPTIONS value. | |
| Modificada | Alta (7.2) | 0.90% | 💥 Exploit | GNU FindutilsSlackware Linux | 31/8/2001 | 16/6/2026 | GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory. |