Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
325 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Scriptbrasil Taboada Macronews | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Baja (2.1) | 0.43% | — | Bcron Project Bcron Exec | 29/9/2014 | 16/6/2026 | bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor. | |
| Modificada | Media (4.3) | 2.0% | — | Wokamoto Wp-cron Dashboard | 3/1/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WP-Cron Dashboard plugin 1.1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the procname parameter to wp-admin/tools.php. | |
| Modificada | Media (4.3) | 1.3% | — | Fedorahosted Cronie | 9/4/2013 | 16/6/2026 | File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab. | |
| Modificada | Baja (3.5) | 0.94% | — | 63reasons Supercron | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SuperCron module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Micronetsoft Rental Property Website | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Micronetsoft RV Dealer Website | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Micronetsoft RV Dealer Website | 1/12/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp. | |
| Modificada | Baja (1.9) | 0.35% | — | Thibault Godouet Fcron | 5/3/2010 | 16/6/2026 | fcrontab in fcron before 3.0.5 allows local users to read arbitrary files via a symlink attack on an unspecified file. | |
| Modificada | Baja (3.3) | 0.35% | — | Fedorahosted CroniePaul Vixie Vixie Cron | 25/2/2010 | 16/6/2026 | The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Micronet Network Access Controller Sp1910 | 8/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Media (4.6) | 0.30% | — | Inotify Incron | 8/10/2009 | 16/6/2026 | incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the process to be run with the incrond supplementary groups and allows local users to gain privileges via an incrontab table. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Minbank Micronation Banking System | 30/1/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Micronation Banking System (minba) 1.5.0 allow remote attackers to execute arbitrary PHP code via a URL in the minsoft_path parameter to (1) utdb_access.php and (2) utgn_message.php in utility/. | |
| Modificada | Media (5) | 1.6% | — | Acronis True Image Echo Server | 13/8/2008 | 16/6/2026 | Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 5.6% | 💥 Exploit | Acronis Snap Deploy | 20/3/2008 | 16/6/2026 | Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Acronis Snap Deploy | 20/3/2008 | 16/6/2026 | The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomplete TFTP request, which triggers a NULL pointer dereference. | |
| Modificada | Media (5) | 2.5% | — | Acronis True ImageAcronis True Image Windows Agent | 10/3/2008 | 16/6/2026 | Acronis True Image Windows Agent 1.0.0.54 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a malformed packet to port 9876, which triggers a NULL pointer dereference. | |
| Modificada | Media (5) | 1.7% | — | Acronis True Image | 10/3/2008 | 16/6/2026 | Acronis True Image Group Server 1.5.19.191 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a packet with an invalid length field, which causes an out-of-bounds read. | |
| Modificada | Alta (10) | 2.6% | — | Micronews | 22/1/2008 | 16/6/2026 | MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php. | |
| Modificada | Baja (2.1) | 0.38% | — | Paul Vixie Vixie Cron | 18/4/2007 | 16/6/2026 | Vixie Cron before 4.1-r10 on Gentoo Linux is installed with insecure permissions, which allows local users to cause a denial of service (cron failure) by creating hard links, which results in a failed st_nlink check in database.c. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Cronosys Cadre PHP Framework | 3/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][framework_path] parameter. | |
| Modificada | Baja (2.1) | 0.33% | — | Inotify Incron | 31/1/2007 | 16/6/2026 | Unspecified vulnerability in inotify before 0.3.5 has unknown impact and attack vectors, related to "access rights to watched files." | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Codemonkeyx Acronym MOD | 31/12/2006 | 16/6/2026 | SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.2) | 0.56% | — | Paul Vixie Vixie Cron | 25/5/2006 | 16/6/2026 | do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits, as originally demonstrated by a program that exceeds the process limits as defined in… | |
| Modificada | Media (5) | 1.6% | — | Thibault Godouet Fcron | 7/2/2006 | 16/6/2026 | convert-fcrontab in Fcron 2.9.5 and 3.0.0 allows remote attackers to create or overwrite arbitrary files via ".." sequences and a symlink attack on the temporary file that is used during conversion. |