Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Teraway Filestream | 12/5/2009 | 16/6/2026 | Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the twFSadmin cookie to 1. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | IBM Tivoli Continuous Data Protection FOR Files | 17/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter. | |
| Modificada | Alta (9.3) | 5.7% | — | HP Openview Performance AgentInnermedia Dynazip MAXInnermedia Dynazip MAX SecureFilestream Turbozip | 13/4/2009 | 16/6/2026 | Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code… | |
| Modificada | Media (5) | 11% | 💥 Exploit | Codecall COM Ionfiles | 6/2/2009 | 16/6/2026 | Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | V3chat V3 Chat Profiles Dating Script | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | V3chat V3 Chat Profiles Dating Script | 31/12/2008 | 16/6/2026 | V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | E107 Alternate Profiles Plugin | 29/10/2008 | 16/6/2026 | SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 6.9% | 💥 Exploit | Alain Barbet Filesys Smbclientparser | 24/7/2008 | 16/6/2026 | The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell metacharacters. | |
| Modificada | Alta (9.3) | 4.8% | — | Tibco Adapter Files Z OSTibco HawkTibco Iprocess EngineTibco Rendezvous+4 | 11/4/2008 | 16/6/2026 | Multiple buffer overflows in TIBCO Software Rendezvous before 8.1.0, as used in multiple TIBCO products, allow remote attackers to execute arbitrary code via a crafted message. | |
| Modificada | Media (6.8) | 21% | 💥 Exploit | Phpprofiles | 27/2/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. | |
| Modificada | Alta (8.5) | 2.1% | — | Drupal Fileshare Module | 15/1/2008 | 16/6/2026 | Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.8) | 4.1% | — | Ext2 Filesystems Utilities E2fsprogs | 7/12/2007 | 16/6/2026 | Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted filesystem image. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM Tivoli Continuous Data Protection FOR Files | 5/11/2007 | 16/6/2026 | IBM Tivoli Continuous Data Protection for Files (CDP) 3.1.0 uses weak permissions (unrestricted write) for the Central Admin Global download directory, which allows local users to place arbitrary files into a location used for updating CDP clients. | |
| Modificada | Media (5) | 9.5% | 💥 Exploit | Joomla Rsfiles | 23/8/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter in a files.display action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Thecreativeheads.de Creative Files | 21/3/2007 | 16/6/2026 | SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL commands via the dlid parameter. | |
| Modificada | Baja (2.1) | 0.48% | — | Phpprofiles | 26/12/2006 | 16/6/2026 | phpProfiles before 2.1.1 does not have an index.php or other index file in the (1) image_data, (2) graphics/comm, or (3) users read/write directories, which might allow remote attackers to list directory contents or have other unknown impacts. | |
| Modificada | Alta (7.5) | 9.5% | 💥 Exploit | Phpprofiles | 26/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the incpath parameter to (3) index.inc.php, (4) account.inc.php, (5)… | |
| Modificada | Media (4.6) | 0.32% | — | Phpprofiles | 26/12/2006 | 16/6/2026 | phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php. | |
| Modificada | Media (6.8) | 6.2% | 💥 Exploit | Phpprofiles | 1/11/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc parameter in users/include/upload_ht.inc.php. | |
| Modificada | Media (5) | 1.7% | — | Curtis Farnham Files Xaraya Module | 7/2/2006 | 16/6/2026 | Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences. | |
| Modificada | Alta (7.5) | 5.6% | — | Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+15 | 30/11/2005 | 16/6/2026 | Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive. | |
| Modificada | Alta (10) | 4.8% | — | Ares Fileshare | 3/8/2005 | 16/6/2026 | Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a (1) long history parameter in the configuration file (ares.conf) or (2) long search string. | |
| Modificada | Media (5) | 1.3% | — | Planetdns Planetfileserver | 6/7/2005 | 16/6/2026 | mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request. | |
| Modificada | Media (4.6) | 0.36% | — | Rsnapshot Filesystem Snapshot Utility | 10/4/2005 | 16/6/2026 | The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files. | |
| Modificada | Alta (7.5) | 2.5% | — | Snapfiles Whisper FTP Surfer | 27/7/2004 | 16/6/2026 | Buffer overflow in Whisper FTP Surfer 1.0.7 allows remote FTP servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long filename. |