Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

279 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Omnistar Interactive Omnistar Article Manager15/11/200616/6/2026
Multiple SQL injection vulnerabilities in OmniStar Article Manager allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in (a) articles/comments.php and (b) articles/article.php, and the (2) page_id parameter in (c) articles/pages.php.
ModificadaAlta (7.5)1.3%💥 ExploitKinesis Interactive Cinema System23/10/200616/6/2026
SQL injection vulnerability in index.asp in Kinesis Interactive Cinema System (KICS) CMS allows remote attackers to execute arbitrary SQL commands via the (1) txtUsername (user) or (2) txtPassword (pass) parameters.
ModificadaMedia (5)1.4%—Xiao Gang WWW Interactive Mathematics Server23/10/200616/6/2026
Unspecified vulnerability in XIAO Gang WWW Interactive Mathematics Server (WIMS) before 3.60 allows remote attackers to modify unspecified data via unspecified vectors involving "variable rights."
ModificadaMedia (6.8)1.6%—Cloudnine Interactive Links Manager24/8/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters.
ModificadaMedia (5.1)1.3%—Cloudnine Interactive Links Manager24/8/200616/6/2026
SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.
ModificadaMedia (6.8)3.1%💥 ExploitFacile Interactive WEB1/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d)…
ModificadaMedia (5.1)6.8%💥 ExploitFacile Interactive WEB1/6/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) pathfile parameter in (a) p-editpage.php and (b) p-editbox.php, and the (2) mytheme and (3) myskin parameters in…
ModificadaAlta (7.5)9.9%💥 ExploitFacile Interactive WEB1/6/200616/6/2026
PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.
ModificadaMedia (5)1.6%—Jaia Interactive Mytopix8/2/200616/6/2026
MyTopix 1.2.3 allows remote attackers to obtain the installation path via a direct request to logon.mod.php, which leaks the path in an error message.
ModificadaMedia (5)1.6%—Jaia Interactive Mytopix8/2/200616/6/2026
MyTopix 1.2.3 allows remote attackers to obtain the installation path via an invalid hl parameter to index.php, which leads to path disclosure, possibly related to invalid SQL syntax.
ModificadaAlta (7.5)1.3%—Jaia Interactive Mytopix8/2/200616/6/2026
SQL injection vulnerability in search.php in MyTopix 1.2.3 allows remote attackers to execute arbitrary SQL commands via the (1) mid and (2) keywords parameters.
ModificadaMedia (4.3)1.8%💥 ExploitCommercial Interactive Media Scoop22/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid…
ModificadaAlta (7.5)13%💥 ExploitInteractive Intelligence Interaction SIP Proxy22/12/200516/6/2026
Heap-based buffer overflow in the SIPParser function in i3sipmsg.dll in Interaction SIP Proxy before 3.0.011 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a REGISTER request with a SPI version number that contains a large number of space or tab characters.
ModificadaAlta (7.5)1.3%—Omnistar Interactive Omnistar Kbase29/11/200516/6/2026
Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php.
ModificadaAlta (7.5)1.2%—Omnistar Interactive Omnistar Live26/11/200516/6/2026
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240.
ModificadaMedia (5)1.4%—Incredible Interactive Dragonfly Commerce12/7/200516/6/2026
Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly…
ModificadaAlta (7.5)1.1%—Incredible Interactive Dragonfly Commerce12/7/200516/6/2026
Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6)…
ModificadaAlta (7.5)1.5%—Interactivephp Fusionbb16/6/200516/6/2026
Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.
ModificadaAlta (7.5)1.1%—Interactivephp Fusionbb13/6/200516/6/2026
Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by the insertUser function, or (2) the bb_session_id value in a cookie.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaMedia (5)1.7%—Nival Interactive EtherlordsNival Interactive Etherlords II31/12/200416/6/2026
Etherlords I 1.07 and earlier and Etherlords II 1.03 and earlier allows remote attackers to cause a denial of service (crash) by sending a packet that specifies the size for the next packet, then sending a larger packet than specified, which causes Etherlords to read unallocated memory.
ModificadaBaja (2.1)1.9%💥 ExploitFreeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+731/12/200416/6/2026
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
ModificadaAlta (7.5)6.3%—Avaya Call Management System ServerAvaya CvlanAvaya Integrated ManagementAvaya Interactive Response+1521/12/200416/6/2026
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
ModificadaAlta (10)6.1%💥 ExploitFreeform Interactive PurgeFreeform Interactive Purge Jihad23/11/200416/6/2026
Buffer overflow in Purge Jihad 2.0.1 and earlier allows remote game servers to execute arbitrary code via an information packet that contains large (1) battle type and (2) map name fields.
ModificadaAlta (10)3.8%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
Orbitaley — Vulnerabilidades