Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 1.5% | — | Planamesa Neooffice | 20/12/2007 | 16/6/2026 | Unspecified vulnerability in OpenOffice.org code in Planamesa NeoOffice 2.2.2 before Patch 4 has unknown impact and attack vectors related to MacOS 10.3.9 .odb files. NOTE: it is not clear whether this issue is a vulnerability. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Neocrome Seditio | 1/12/2007 | 16/6/2026 | SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers to execute arbitrary SQL commands via the pag_sub[] parameter to plug.php. | |
| Modificada | Media (4.3) | 1.9% | — | Oneorzero Helpdesk | 30/10/2007 | 16/6/2026 | Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Joomla Neorecruit | 23/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an offer_view action. | |
| Modificada | Media (6.5) | 2.1% | 💥 Exploit | Neocrome Seditio | 30/7/2007 | 16/6/2026 | Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users to upload arbitrary PHP code via a filename ending with (1) .php.gif, (2) .php.jpg, or (3) .php.png. | |
| Modificada | Alta (10) | 3.3% | — | Zoneo-soft Phptraffica | 10/7/2007 | 16/6/2026 | The isloggedin function in Php/login.inc.php in phpTrafficA 1.4.3 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the username cookie to "traffic." NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Zoneo-soft Phptraffica | 27/6/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbitrary local files via the lang parameter, a different vector and version than CVE-2007-1076.2. | |
| Modificada | Media (4.3) | 0.84% | — | Zoneo-soft Phptraffica | 27/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpTrafficA before 1.2beta2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to keywords results in the (1) main, (2) daily, (3) weekly, (4) monthly, (5) new trends, (6) individual page, and (7) search engine statistics. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Zoneo-soft Phptraffica | 27/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Zoneo-soft Phptraffica | 27/6/2007 | 16/6/2026 | SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a stats action. | |
| Modificada | Alta (7.5) | 1.3% | — | Zoneo-soft Phptraffica | 27/6/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in phpTrafficA before 1.4.2 allow remote attackers to have an unknown impact via the file parameter to (1) plotStatBar.php or (2) plotStatPie.php, different vectors than CVE-2007-1076. | |
| Modificada | Alta (10) | 3.8% | 💥 Exploit | Neon Labs Website | 25/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Zoneo-soft Freeforum | 25/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in FreeForum 0.9.0 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter. NOTE: this issue has been disputed by third party researchers, stating that fpath variable is initialized before being used | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Alta (7.8) | 2.2% | — | Neon | 9/1/2007 | 16/6/2026 | Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a… | |
| Modificada | Alta (7.5) | 1.1% | — | Neocrome Land Down Under | 31/12/2006 | 16/6/2026 | SQL injection vulnerability in Journal.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the w parameter to journal.php. | |
| Modificada | Alta (7.5) | 56% | 💥 Exploit | Mcafee NeotraceMcafee Visual Trace | 23/12/2006 | 16/6/2026 | Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (aka McAfee Visual Trace) 3.25 allows remote attackers to execute arbitrary code via a long argument string to the TraceTarget method. NOTE: The provenance of this… | |
| Modificada | Media (4.9) | 0.81% | — | Neoscale Systems Cryptostor Tape 700 | 19/12/2006 | 16/6/2026 | The NeoScale Systems CryptoStor 700 series appliance before 2.6 relies on client-side ActiveX code for smartcard authentication, which allows remote attackers to bypass smartcard authentication, and gain access if able to present a valid username and password, by disabling ActiveX. | |
| Modificada | Media (6.8) | 1.0% | 💥 Exploit | Neocrome Land Down UnderNeocrome Seditio | 15/12/2006 | 16/6/2026 | SQL injection vulnerability in polls.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.96% | — | Neocrome Seditio | 7/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Neocrome Seditio 1.10 and earlier have unknown impact and attack vectors related to (1) plugins/ipsearch/ipsearch.admin.php, and (2) pfs/pfs.edit.inc.php, (3) users/users.register.inc.php in system/core. NOTE: the users.profile.inc.php vector is identified by CVE-2006-6177.… | |
| Modificada | Media (6.8) | 1.2% | 💥 Exploit | Neocrome Seditio | 7/12/2006 | 16/6/2026 | SQL injection vulnerability in polls.php in Neocrome Seditio 1.10 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 2.0% | — | Neocrome Land Down Under | 4/12/2006 | 16/6/2026 | SQL injection vulnerability in system/core/profile/profile.inc.php in Neocrome Land Down Under (LDU) 8.x and earlier allows remote authenticated users to execute arbitrary SQL commands via a url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by a… | |
| Modificada | Media (5) | 2.3% | — | Neoengine | 2/12/2006 | 16/6/2026 | The Core::Receive function in neonet/core.cpp for NeoEngine 0.8.2 and earlier, and CVS 3422, allow remote attackers to cause a denial of service (engine crash) via a message with a large uiMessageLength that produces a failed memory allocation and a null pointer dereference. | |
| Modificada | Alta (7.5) | 2.6% | — | Neoengine | 2/12/2006 | 16/6/2026 | Multiple format string vulnerabilities in NeoEngine 0.8.2 and earlier, and CVS 3422, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Console::Render in neoengine/console.cpp and (2) TextArea::Render in neowtk/textarea.cpp. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Neocrome Seditio | 30/11/2006 | 16/6/2026 | SQL injection vulnerability in system/core/users/users.profile.inc.php in Neocrome Seditio 1.10 and earlier allows remote authenticated users to execute arbitrary SQL commands via a double-url-encoded id parameter to users.php that begins with a valid filename, as demonstrated by "default.gif" followed by an encoded… |