Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
279 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Omnistar Interactive Omnistar Article Manager | 15/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in OmniStar Article Manager allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in (a) articles/comments.php and (b) articles/article.php, and the (2) page_id parameter in (c) articles/pages.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Kinesis Interactive Cinema System | 23/10/2006 | 16/6/2026 | SQL injection vulnerability in index.asp in Kinesis Interactive Cinema System (KICS) CMS allows remote attackers to execute arbitrary SQL commands via the (1) txtUsername (user) or (2) txtPassword (pass) parameters. | |
| Modificada | Media (5) | 1.4% | — | Xiao Gang WWW Interactive Mathematics Server | 23/10/2006 | 16/6/2026 | Unspecified vulnerability in XIAO Gang WWW Interactive Mathematics Server (WIMS) before 3.60 allows remote attackers to modify unspecified data via unspecified vectors involving "variable rights." | |
| Modificada | Media (6.8) | 1.6% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters. | |
| Modificada | Media (5.1) | 1.3% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter. | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Facile Interactive WEB | 1/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d)… | |
| Modificada | Media (5.1) | 6.8% | 💥 Exploit | Facile Interactive WEB | 1/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) pathfile parameter in (a) p-editpage.php and (b) p-editbox.php, and the (2) mytheme and (3) myskin parameters in… | |
| Modificada | Alta (7.5) | 9.9% | 💥 Exploit | Facile Interactive WEB | 1/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter. | |
| Modificada | Media (5) | 1.6% | — | Jaia Interactive Mytopix | 8/2/2006 | 16/6/2026 | MyTopix 1.2.3 allows remote attackers to obtain the installation path via a direct request to logon.mod.php, which leaks the path in an error message. | |
| Modificada | Media (5) | 1.6% | — | Jaia Interactive Mytopix | 8/2/2006 | 16/6/2026 | MyTopix 1.2.3 allows remote attackers to obtain the installation path via an invalid hl parameter to index.php, which leads to path disclosure, possibly related to invalid SQL syntax. | |
| Modificada | Alta (7.5) | 1.3% | — | Jaia Interactive Mytopix | 8/2/2006 | 16/6/2026 | SQL injection vulnerability in search.php in MyTopix 1.2.3 allows remote attackers to execute arbitrary SQL commands via the (1) mid and (2) keywords parameters. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Commercial Interactive Media Scoop | 22/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid… | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Interactive Intelligence Interaction SIP Proxy | 22/12/2005 | 16/6/2026 | Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a REGISTER request with a SPI version number that contains a large number of space or tab characters. | |
| Modificada | Alta (7.5) | 1.3% | — | Omnistar Interactive Omnistar Kbase | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Omnistar Interactive Omnistar Live | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240. | |
| Modificada | Media (5) | 1.4% | — | Incredible Interactive Dragonfly Commerce | 12/7/2005 | 16/6/2026 | Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly… | |
| Modificada | Alta (7.5) | 1.1% | — | Incredible Interactive Dragonfly Commerce | 12/7/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6)… | |
| Modificada | Alta (7.5) | 1.5% | — | Interactivephp Fusionbb | 16/6/2005 | 16/6/2026 | Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Interactivephp Fusionbb | 13/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by the insertUser function, or (2) the bb_session_id value in a cookie. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (5) | 1.7% | — | Nival Interactive EtherlordsNival Interactive Etherlords II | 31/12/2004 | 16/6/2026 | Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (crash) by sending a packet that specifies the size for the next packet, then sending a larger packet than specified, which causes Etherlords to read unallocated memory. | |
| Modificada | Baja (2.1) | 1.9% | 💥 Exploit | Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+7 | 31/12/2004 | 16/6/2026 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. | |
| Modificada | Alta (7.5) | 6.3% | — | Avaya Call Management System ServerAvaya CvlanAvaya Integrated ManagementAvaya Interactive Response+15 | 21/12/2004 | 16/6/2026 | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow. | |
| Modificada | Alta (10) | 6.1% | 💥 Exploit | Freeform Interactive PurgeFreeform Interactive Purge Jihad | 23/11/2004 | 16/6/2026 | Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields. | |
| Modificada | Alta (10) | 3.8% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. |