Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | Phpmyadmin | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Phpmyadmin | 21/12/2005 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.7.0 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag to server_privileges.php, as demonstrated using the dbname and checkprivs parameters. NOTE: the provenance of this issue is unknown, although third… | |
| Modificada | Media (6.3) | 1.4% | — | Phpmyadmin | 19/12/2005 | 16/6/2026 | ** DISPUTADA ** Vulnerabilidad de inyección de SQL en server_privileges.php en phpMyAdmin 2.7.0 permite a atacantes remotos ejecutar órdenes SQL de su elección mediante los parámetros (1)dbname y (2) checkprivs. NOTA: el fabricante y una tercera parte disputan esta cuestión, diciendo que la tarea principal del… | |
| Modificada | Media (4.3) | 1.8% | — | Phpmyadmin | 8/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.7.0 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP_HOST variable and (2) various scripts in the libraries directory that handle header generation. | |
| Modificada | Media (5) | 2.4% | — | Phpmyadmin | 8/12/2005 | 16/6/2026 | The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables. | |
| Modificada | Media (4.3) | 1.2% | — | Phpmyadmin | 24/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog. | |
| Modificada | Media (5) | 1.7% | — | Phpmyadmin | 16/11/2005 | 16/6/2026 | phpMyAdmin 2.7.0-beta1 y anteriores permiten a atacantes remotos obtener la ruta completa del servidor mediante peticiones directas a varios scripts en el directorio de bibliotecas. | |
| Modificada | Media (5) | 1.6% | — | Phpmyadmin | 16/11/2005 | 16/6/2026 | Vulnerabilidad de inyección de CRLF en phpMyAdmin anteriores a 2.6.4-pl4 permite a atacantes remotos conducir ataques de separación de respuesta HTTP mediante scripts no especificados. | |
| Modificada | Media (4.3) | 5.6% | 💥 Exploit | Phpmyadmin | 24/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Phpmyadmin | 23/10/2005 | 16/6/2026 | PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array. | |
| Modificada | Media (5) | 2.7% | — | Phpmyadmin | 23/10/2005 | 16/6/2026 | The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying… | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Phpmyadmin | 8/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php. | |
| Modificada | Media (4.6) | 0.36% | — | Phpmyadmin | 3/5/2005 | 16/6/2026 | The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script. | |
| Modificada | Media (5) | 1.5% | — | Phpmyadmin | 2/5/2005 | 16/6/2026 | phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php,… | |
| Modificada | Media (4.6) | 0.69% | — | Phpmyadmin | 2/5/2005 | 16/6/2026 | phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Phpmyadmin | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter. | |
| Modificada | Media (5) | 1.4% | — | Phpmyadmin | 2/5/2005 | 16/6/2026 | phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message. | |
| Modificada | Alta (7.5) | 2.7% | — | Phpmyadmin | 2/5/2005 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (6.8) | 1.5% | — | PhpmyadminGentoo Linux | 1/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin… | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Phpmyadmin | 24/2/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter… | |
| Modificada | Media (5) | 1.4% | — | Phpmyadmin | 10/1/2005 | 16/6/2026 | phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Phpmyadmin | 10/1/2005 | 16/6/2026 | phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters. | |
| Modificada | Alta (7.5) | 2.9% | — | Phpmyadmin | 31/12/2004 | 16/6/2026 | The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors. | |
| Modificada | Alta (7.5) | 3.8% | — | Phpmyadmin | 31/12/2004 | 16/6/2026 | phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables. | |
| Modificada | Alta (7.5) | 9.4% | 💥 Exploit | Phpmyadmin | 31/12/2004 | 16/6/2026 | Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name. |