Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

312 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.3%—Community Link PRO WEB Editor5/7/200516/6/2026
login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.
ModificadaMedia (4.3)0.46%—Invisioncommunity Gallery9/6/200516/6/2026
Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.
ModificadaAlta (7.5)1.3%—Invision Power Services Invision Community Blog9/6/200516/6/2026
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action.
ModificadaMedia (4.3)1.2%—Invision Power Services Invision Community Blog9/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.
ModificadaAlta (7.5)1.3%—Invision Power Services Invision Community Blog2/5/200516/6/2026
SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.
ModificadaAlta (10)8.4%—Abisource Community AbiwordWvware6/8/200416/6/2026
Buffer overflow in the wvHandleDateTimePicture function in wv library (wvWare) 0.7.4 through 0.7.6 and 1.0.0 allows remote attackers to execute arbitrary code via a document with a long DateTime field.
ModificadaBaja (2.1)0.47%—Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Admin-cd FOR FirewallSuse Linux Connectivity Server+136/8/200416/6/2026
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.
ModificadaAlta (7.5)21%—Andrew Tridgell RsyncRedhat RsyncEngardelinux Secure CommunityEngardelinux Secure Linux+115/12/200316/6/2026
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
ModificadaMedia (4.3)1.2%—Zack Coburn Meunity Community System31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Meunity Community System 1.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag when creating a topic.
ModificadaAlta (7.5)1.8%—Infopop Ultimate Bulletin BoardWired Community Software Wwwthreads16/5/200216/6/2026
Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.
ModificadaAlta (10)2.6%—Nara Vision Kebi Community8/12/200116/6/2026
Kebi WebMail allows remote attackers to access the administrator menu and gain privileges via the /a/ hidden directory, which is installed under the web document root.
ModificadaAlta (7.5)5.5%💥 ExploitWired Community Software Wwwthreads3/2/200016/6/2026
wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.
Orbitaley — Vulnerabilidades