Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
312 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Community Link PRO WEB Editor | 5/7/2005 | 16/6/2026 | login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter. | |
| Modificada | Media (4.3) | 0.46% | — | Invisioncommunity Gallery | 9/6/2005 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions. | |
| Modificada | Alta (7.5) | 1.3% | — | Invision Power Services Invision Community Blog | 9/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. | |
| Modificada | Media (4.3) | 1.2% | — | Invision Power Services Invision Community Blog | 9/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data. | |
| Modificada | Alta (7.5) | 1.3% | — | Invision Power Services Invision Community Blog | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Alta (10) | 8.4% | — | Abisource Community AbiwordWvware | 6/8/2004 | 16/6/2026 | Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 through 0.7.6 and 1.0.0 allows remote attackers to execute arbitrary code via a document with a long DateTime field. | |
| Modificada | Baja (2.1) | 0.47% | — | Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Admin-cd FOR FirewallSuse Linux Connectivity Server+13 | 6/8/2004 | 16/6/2026 | The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources. | |
| Modificada | Alta (7.5) | 21% | — | Andrew Tridgell RsyncRedhat RsyncEngardelinux Secure CommunityEngardelinux Secure Linux+1 | 15/12/2003 | 16/6/2026 | Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail. | |
| Modificada | Media (4.3) | 1.2% | — | Zack Coburn Meunity Community System | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Meunity Community System 1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag when creating a topic. | |
| Modificada | Alta (7.5) | 1.8% | — | Infopop Ultimate Bulletin BoardWired Community Software Wwwthreads | 16/5/2002 | 16/6/2026 | Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension. | |
| Modificada | Alta (10) | 2.6% | — | Nara Vision Kebi Community | 8/12/2001 | 16/6/2026 | Kebi WebMail allows remote attackers to access the administrator menu and gain privileges via the /a/ hidden directory, which is installed under the web document root. | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Wired Community Software Wwwthreads | 3/2/2000 | 16/6/2026 | wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums. |