Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Neocrome Seditio | 17/11/2012 | 16/6/2026 | Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql. | |
| Modificada | Media (5) | 1.2% | — | Neocrome Seditio | 17/11/2012 | 16/6/2026 | Neocrome Seditio build 161 and earlier allows remote attackers to obtain sensitive information via direct request to (1) view.php, (2) plugins/contact/lang/contact.en.lang.php, (3) system/lang/en/main.lang.php, (4) system/lang/en/message.lang.php, or (5) system/core/view/view.inc.php, which reveals the installation… | |
| Modificada | Baja (2.6) | 1.3% | — | Neocrome Seditio | 17/11/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or HTML via the (1) newmsg or (2) rtext parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Oneorzero Action AND Information Management System | 1/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in OneOrZero AIMS 2.8.0 Trial Edition build231211 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Thomas Hunter Neoinvoice | 26/8/2012 | 16/6/2026 | SQL injection vulnerability in application/controllers/invoice.php in NeoInvoice might allow remote attackers to execute arbitrary SQL commands via vectors involving the sort_col variable in the list_items function, a different vulnerability than CVE-2012-3477. | |
| Modificada | Alta (7.5) | 1.2% | — | Thomas Hunter Neoinvoice | 26/8/2012 | 16/6/2026 | SQL injection vulnerability in signup_check.php in NeoInvoice allows remote attackers to execute arbitrary SQL commands via the value parameter in a username action. | |
| Modificada | Media (5.8) | 1.3% | — | Neoaxis WEB Player | 20/1/2012 | 16/6/2026 | Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Neojoomla COM Neorecruit | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in the NeoRecruit (com_neorecruit) component 1.6.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in an offer_view action to index.php, a different vector than CVE-2007-4506. | |
| Modificada | Alta (7.5) | 1.3% | — | Oneorzero Aims | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in lib/ooz_access.php in OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to execute arbitrary SQL commands via the cookieName variable. | |
| Modificada | Alta (10) | 3.1% | — | Oneorzero Aims | 1/11/2011 | 16/6/2026 | OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie. | |
| Modificada | Media (4) | 2.3% | 💥 Exploit | Oneorzero Aims | 14/9/2011 | 16/6/2026 | Directory traversal vulnerability in index.php in OneOrZero AIMS 2.6.0 Members Edition allows remote authenticated users to read arbitrary files via directory traversal sequences in the controller parameter in a show_report action. | |
| Modificada | Media (6.5) | 0.90% | 💥 Exploit | Oneorzero Aims | 14/9/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in OneOrZero AIMS 2.6.0 Members Edition and 2.7.0 Trial Edition allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter in a saved_search action and (2) item_types parameter in a show_item_search action in the… | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | G4j.laoneo COM Gcalendar | 16/3/2010 | 16/6/2026 | Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | G4j.laoneo COM Gcalendar | 29/11/2009 | 16/6/2026 | SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the gcid parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Danneo CMS | 9/9/2009 | 16/6/2026 | SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php, related to incorrect input sanitization… | |
| Modificada | Media (5.8) | 1.5% | — | Webdav NeonApple MAC OS XCanonical Ubuntu LinuxFedoraproject Fedora | 21/8/2009 | 16/6/2026 | neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification… | |
| Modificada | Media (4.3) | 8.4% | 💥 Exploit | Webdav Neon | 21/8/2009 | 16/6/2026 | neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Neocrome Seditio | 24/4/2009 | 16/6/2026 | SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php. | |
| Modificada | Alta (7.8) | 9.7% | 💥 Exploit | TP Neostrada Livebox Adsl Router | 20/3/2009 | 16/6/2026 | The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI. | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Oneorzero Helpdesk | 12/3/2009 | 16/6/2026 | Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter. | |
| Modificada | Media (4.3) | 2.3% | — | Webdav Neon | 27/8/2008 | 16/6/2026 | neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Zoneo-soft Freeforum | 10/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter to (1) the default URI or (2) index.php, or (3) the PATH_INFO to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (6.8) | 0.85% | 💥 Exploit | Danneo CMS | 25/3/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Joomla COM NeogalleryMambo COM Neogallery | 13/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM NeoreferencesMambo COM Neoreferences | 12/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter. |