Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 12% | — | Microsoft Hyperlink Object Library | 9/8/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Hyperlink Object Library (hlink.dll), possibly a buffer overflow, allows user-assisted attackers to execute arbitrary code via crafted hyperlinks that are not properly handled when hlink.dll "uses a file containing a malformed function," aka "Hyperlink Object Function… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Knusperleicht Guestbook | 7/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Knusperleicht FAQ | 7/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the faq_path parameter. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Knusperleicht Newsletter | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH parameter. | |
| Modificada | Media (5.1) | 3.4% | 💥 Exploit | Knusperleicht Shoutbox | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter. | |
| Modificada | Media (5.1) | 3.2% | 💥 Exploit | Knusperleicht Newsreporter | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the news_include_path parameter. | |
| Modificada | Media (5.1) | 3.2% | 💥 Exploit | Knusperleicht Filemanager | 5/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) dwl_download_path or (2) dwl_include_path parameters. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Knusperleicht Quickie | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in quickie.php in Knusperleicht Quickie, probably 0.2, allows remote attackers to execute arbitrary PHP code via a URL in the QUICK_PATH parameter. | |
| Modificada | Alta (9.3) | 56% | 💥 Exploit | Microsoft Hyperlink Object Library | 19/6/2006 | 16/6/2026 | Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode,… | |
| Modificada | Media (4.6) | 0.38% | — | Activestate Activeperl | 6/6/2006 | 16/6/2026 | ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by creating a malicious sitecustomize.pl file in that directory. NOTE: The provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | PerlpodderProdder | 23/5/2006 | 16/6/2026 | Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget. | |
| Modificada | Media (5.1) | 4.3% | — | Perlpodder | 23/5/2006 | 16/6/2026 | perlpodder before 0.5 allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast, which are executed when saving the URL to a log file. NOTE: the wget vector is already covered by CVE-2006-2548. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Perlcoders Group Bannerfarm | 20/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters. | |
| Modificada | Media (5) | 1.9% | — | Perlblog | 19/2/2006 | 16/6/2026 | Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | Perlblog | 19/2/2006 | 16/6/2026 | Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body… | |
| Modificada | Media (4.3) | 1.3% | — | Perlblog | 19/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters. | |
| Modificada | Baja (2.1) | 0.36% | — | Debian Libmail-audit-perl | 31/12/2005 | 16/6/2026 | Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file. | |
| Modificada | Alta (7.2) | 0.40% | — | Larry Wall Perl | 16/12/2005 | 16/6/2026 | Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH. | |
| Modificada | Media (4.3) | 1.5% | — | Acme Labs Perlcal | 11/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter. | |
| Modificada | Media (4.6) | 1.4% | — | Perl | 1/12/2005 | 16/6/2026 | Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using… | |
| Modificada | Media (4.3) | 1.4% | — | Scriptsolutions Perldiver | 27/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged. | |
| Modificada | Media (4.3) | 1.3% | — | Scriptsolutions Perldiver | 27/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in perldiver.cgi in PerlDiver 2.x allows remote attackers to inject arbitrary web script or HTML via the module parameter. | |
| Modificada | Media (5) | 1.1% | — | Thesitewizard.com Chfeedback.pl Feedback Form Perl Script | 8/9/2005 | 16/6/2026 | CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers. | |
| Modificada | Alta (7.5) | 1.6% | — | Knusperleicht Shoutbox Script | 2/5/2005 | 16/6/2026 | Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes. | |
| Modificada | Media (4.6) | 1.2% | 💥 Exploit | Larry Wall Perl | 2/5/2005 | 16/6/2026 | The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable. |