Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.5% | — | Mailenable EnterpriseMailenable ProfessionalMailenable Standard | 7/9/2006 | 16/6/2026 | SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via an SPF lookup for a domain with a large number of records, which triggers a null pointer exception. | |
| Modificada | Media (5.1) | 3.1% | — | Cimmetry Systems Autovue Solidmodel Professional | 28/7/2006 | 16/6/2026 | Stack-based buffer overflow in AutoVue SolidModel Professional Desktop Edition 19.1 Build 5993 allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) ARJ, (2) RAR, or (3) ZIP archive. | |
| Modificada | Media (5) | 1.2% | — | Professional Home Page Tools Guestbook | 25/7/2006 | 16/6/2026 | delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obtain the administrator's password hash after logout. | |
| Modificada | Alta (7.5) | 1.5% | — | Professional Home Page Tools Guestbook | 21/7/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in class.php in Professional Home Page Tools Guestbook allow remote attackers to execute arbitrary SQL commands via the (1) hidemail, (2) name, (3) mail, (4) ip, or (5) text parameters. | |
| Modificada | Media (6.4) | 1.2% | — | Professional Home Page Tools Guestbook | 21/7/2006 | 16/6/2026 | setcookie.php for the administration login in Professional Home Page Tools Guestbook records the hash of the administrator password in a cookie, which allows attackers to conduct brute force password guessing attacks after obtaining the hash. | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | Mailenable EnterpriseMailenable Professional | 28/6/2006 | 16/6/2026 | The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a… | |
| Modificada | Alta (7.5) | 2.4% | — | Picturedis PhotoalbumPicturedis Professional | 19/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PictureDis Professional 1.33 Build 234 and earlier and PictureDis Photoalbum 4.82 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to files in photoalbum/ including (1) thumstbl.php, (2) wpfiles.php, and (3)… | |
| Modificada | Media (6.5) | 1.1% | — | Hitachi EUR Print ServiceHitachi EUR Print Service FOR ILFHitachi EUR ProfessionalHitachi EUR Viewer | 22/5/2006 | 16/6/2026 | SQL injection vulnerability in Hitachi EUR Professional Edition, EUR Viewer, EUR Print Service, and EUR Print Service for ILF allows remote authenticated users to execute arbitrary SQL commands via unknown attack vectors. | |
| Modificada | Media (5) | 5.5% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network nodes via a modified nDeviceGroupID parameter. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b)… | |
| Modificada | Media (5) | 3.1% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possibly (2) sRedirectUrl parameters. | |
| Modificada | Media (5) | 3.8% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid usernames. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (5) | 3.8% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 2.5% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unknown vectors in (1) NmConsole/Tools.asp and (2) NmConsole/DeviceSelection.asp. NOTE: the provenance of this information is… | |
| Modificada | Media (5) | 3.5% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain source code for scripts via a trailing dot in a request to NmConsole/Login.asp. | |
| Modificada | Alta (10) | 1.8% | — | Mailenable EnterpriseMailenable ProfessionalMailenable Standard | 15/4/2006 | 16/6/2026 | Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits". NOTE: this is a different set of affected versions, and probably a different… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Internet Solutions Professionals Site MAN | 2/4/2006 | 16/6/2026 | SQL injection vulnerability in admin_login.asp in ISP of Egypt SiteMan allows remote attackers to execute arbitrary SQL commands via the pass parameter. | |
| Modificada | Media (5) | 2.4% | — | Mailenable EnterpriseMailenable Professional | 21/3/2006 | 16/6/2026 | Webmail in MailEnable Professional Edition before 1.73 and Enterprise Edition before 1.21 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors involving "incorrectly encoded quoted-printable emails". | |
| Modificada | Media (5) | 2.3% | — | Mailenable Professional | 1/2/2006 | 16/6/2026 | IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Discusware Discus FreewareDiscusware Discus Professional | 4/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DiscusWare Discus Freeware 3.10.5 and Professional 3.10.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in a URL, which is not properly sanitized from the resulting error message. NOTE: the provenance of this information is unknown;… | |
| Modificada | Alta (7.8) | 7.1% | 💥 Exploit | Mailenable EnterpriseMailenable Professional | 21/12/2005 | 16/6/2026 | Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) LIST, (2) LSUB, and (3) UID FETCH commands. NOTE: it is possible that these are alternate vectors for the issue… | |
| Modificada | Media (6.5) | 4.3% | 💥 Exploit | Mailenable EnterpriseMailenable Professional | 20/12/2005 | 16/6/2026 | Buffer overflow in MailEnable Professional 1.71 and earlier, and Enterprise 1.1 and earlier, allows remote authenticated users to execute arbitrary code via a long IMAP EXAMINE command. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Cfmagic Magic Book PersonalCfmagic Magic Book Professional | 12/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in book.cfm in Magic Book Personal and Professional 2.0 allows remote attackers to inject arbitrary web script or HTML via the StartRow parameter. | |
| Modificada | Alta (7.8) | 2.1% | — | Soti Pocket Controller-professional | 11/12/2005 | 16/6/2026 | Soti Pocket Controller-Professional 5.0 allows remote attackers to turn off, reboot, or hard reset a PDA via a series of initialization, command, and reset packets sent to port 5492. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Web4future Edating Professional | 6/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web4Future eDating Professional 5 allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) pg, and (3) sortb parameters to (a) index.php; (4) cid parameter to (b) gift.php and (c) fq.php; and (5) cat parameter to (d) articles.php. |