Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 2.2% | — | Dotclear | 11/6/2014 | 17/6/2026 | The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request. | |
| Modificada | Media (6) | 1.7% | — | Dotclear | 22/5/2014 | 17/6/2026 | SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter. | |
| Modificada | Media (6.5) | 3.6% | 💥 Exploit | Dotonpaper Booking System | 22/5/2014 | 17/6/2026 | SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the booking_form_id parameter to wp-admin/admin-ajax.php. | |
| Modificada | Alta (7.5) | 2.3% | — | Dotclear | 16/5/2014 | 17/6/2026 | Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php. | |
| Modificada | Media (4.3) | 1.2% | — | Slashes&dots Offria | 8/5/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php. | |
| Modificada | Media (4.3) | 1.9% | — | Dotcms | 2/4/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) _loginUserName parameter to application/login/login.html, (2) my_account_login parameter to c/portal_public/login, or (3) email parameter to forgotPassword. | |
| Modificada | Media (4.3) | 1.2% | — | Dnnsoftware Dotnetnuke | 12/3/2014 | 17/6/2026 | Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 2.5% | — | Dnnsoftware Dotnetnuke | 12/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI. | |
| Modificada | Baja (3.5) | 0.94% | — | Dnnsoftware Dotnetnuke | 12/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile. | |
| Modificada | Media (5) | 1.3% | — | Dotnetblogengine Blogengine.net | 3/1/2014 | 17/6/2026 | BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file. | |
| Modificada | Baja (2.6) | 7.9% | — | Apache MOD DontdothatApache Subversion | 7/12/2013 | 16/6/2026 | The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Neubivljiv Dota Openstats | 25/10/2012 | 16/6/2026 | SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | |
| Modificada | Media (6) | 2.2% | — | Dotcms | 8/6/2012 | 16/6/2026 | dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template. | |
| Modificada | Media (4.3) | 0.92% | — | Dnnsoftware DotnetnukeDotnetnuke | 11/4/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message. | |
| Modificada | Media (4.3) | 0.92% | — | Dnnsoftware Dotnetnuke | 11/4/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used within a modal popup. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Dotclear | 19/3/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7)… | |
| Modificada | Alta (7.5) | 3.3% | — | Dotclear | 19/3/2012 | 16/6/2026 | Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory. | |
| Modificada | Media (5) | 1.3% | — | Dotproject | 23/9/2011 | 16/6/2026 | dotproject 2.1.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by style/dp-grey-theme/footer.php and certain other files. | |
| Modificada | Alta (7.5) | 1.7% | — | 9.dotpp.net Megalith | 15/9/2011 | 16/6/2026 | Unspecified vulnerability in Megalith 12th edition through 27th edition allows remote attackers to gain administrative privileges via unknown vectors. | |
| Modificada | Media (6.5) | 1.7% | — | Dotclear | 8/6/2011 | 16/6/2026 | The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allows remote authenticated users to upload and execute arbitrary PHP code via the media_path or media_file parameter. NOTE: some of these details are obtained from third… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Dnnsoftware Dotnetnuke | 9/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5.8) | 1.4% | — | Cybozu OfficeCybozu Dotsales | 24/5/2010 | 16/6/2026 | Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone. | |
| Modificada | Media (4.3) | 1.7% | — | Dnnsoftware Dotnetnuke | 29/11/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page. | |
| Modificada | Media (5) | 1.2% | — | Dnnsoftware Dotnetnuke | 29/11/2009 | 16/6/2026 | The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information. | |
| Modificada | Alta (7.5) | 1.4% | — | Dnnsoftware Dotnetnuke | 27/8/2009 | 16/6/2026 | DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation. |