Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | Bernard Pacques YET Another Community System CMS | 6/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2) categories/category.php, (3) categories/populate.php, (4) comments/populate.php,… | |
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | Bernard Pacques YET Another Community System CMS | 1/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter. | |
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | Interact Learning Community Environment Interact | 30/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b) includes/common.inc.php, and the (2) CONFIG[LANGUAGE_CPATH] parameter in (c)… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | BlackboardBlackboard Learning AND Community Portal SuiteBlackboard Vista | 23/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML… | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Wired Community Software Wwwthreads | 27/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to inject arbitrary web script or HTML via the week parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the uid parameter in the rss page. | |
| Modificada | Alta (7.5) | 1.3% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | SQL injection vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to execute arbitrary SQL commands via the browse parameter. | |
| Modificada | Media (6.8) | 1.4% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved… | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Phpcommunitycalendar | 3/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Phpcommunitycalendar | 3/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4)… | |
| Modificada | Media (6.8) | 1.5% | — | DokeosDokeos Community Release | 10/5/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allow remote attackers to execute arbitrary PHP code via a URL in the (1) rootSys and (2) clarolineRepositorySys parameters, and possibly the (3) lang_path, (4)… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Creative Software Community Portal | 9/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4)… | |
| Modificada | Media (6.4) | 1.4% | — | Invision Power Services Invision Community Blog | 9/5/2006 | 16/6/2026 | SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Community Architect Guestbook | 25/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed by fsguestbook.html. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (6.4) | 1.3% | — | Wired Community Software Wwwthreads | 21/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in WWWThreads RC 3 allow remote attackers to execute arbitrary SQL commands via (1) the forumreferrer cookie to register.php and (2) the messages parameter in message_list.php. | |
| Modificada | Media (4.3) | 1.5% | — | Communityserver.org Community Server | 4/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: this candidate does not contain any actionable or distinguishing information. Perhaps it should not be included in CVE. NOTE: the provenance of this… | |
| Modificada | Media (4.3) | 1.2% | — | Citysoft Community Enterprise | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in CitySoft Community Enterprise 4.x allows remote attackers to inject arbitrary web script or HTML via the (1) presentationSite, (2) docPublishYear, (3) docDescription, (4) publishState, (5) docAuthor, (6) docTitle, (7) subTopic, (8) topic, (9) topicRadio, (10)… | |
| Modificada | Media (6.4) | 1.4% | — | Citysoft Community Enterprise | 20/12/2005 | 16/6/2026 | CitySoft Community Enterprise 4.x allows remote attackers to obtain the full path of the server via an invalid (1) fuseaction parameter to index.cfm and (2) documentid parameter to document/docWindow.cfm. | |
| Modificada | Alta (7.5) | 1.3% | — | Citysoft Community Enterprise | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in CitySoft Community Enterprise 4.x allows remote attackers to execute arbitrary SQL commands via the (1) nodeID, (2) pageID, (3) ID, and (4) parentid parameter to index.cfm; and (5) documentFormatId parameter to document/docWindow.cfm. | |
| Modificada | Media (5.1) | 4.1% | — | Abisource Community Abiword | 23/10/2005 | 16/6/2026 | Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions… | |
| Modificada | Alta (7.5) | 4.6% | — | Abisource Community Abiword | 28/9/2005 | 16/6/2026 | Stack-based buffer overflow in AbiWord before 2.2.10 allows attackers to execute arbitrary code via the RTF import mechanism. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via the (1) login field in login.php or (2) LocationID parameter to week.php. | |
| Modificada | Media (4.3) | 1.3% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the LocationID parameter to (1) thankyou.php or (2) day.php, font parameter to (3) calDaily.php, (4) calMonthly.php, (5) calMonthlyP.php,… | |
| Modificada | Alta (7.5) | 1.8% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory. | |
| Modificada | Media (4.3) | 0.97% | — | Telligent Systems Community Server Forums | 5/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter. |