Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

355 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)12%—Microsoft Hyperlink Object Library9/8/200616/6/2026
Unspecified vulnerability in Microsoft Hyperlink Object Library (hlink.dll), possibly a buffer overflow, allows user-assisted attackers to execute arbitrary code via crafted hyperlinks that are not properly handled when hlink.dll "uses a file containing a malformed function," aka "Hyperlink Object Function…
ModificadaAlta (7.5)2.6%💥 ExploitKnusperleicht Guestbook7/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.
ModificadaAlta (7.5)2.6%💥 ExploitKnusperleicht FAQ7/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the faq_path parameter.
ModificadaAlta (7.5)3.4%💥 ExploitKnusperleicht Newsletter5/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH parameter.
ModificadaMedia (5.1)3.4%💥 ExploitKnusperleicht Shoutbox5/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter.
ModificadaMedia (5.1)3.2%💥 ExploitKnusperleicht Newsreporter5/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the news_include_path parameter.
ModificadaMedia (5.1)3.2%💥 ExploitKnusperleicht Filemanager5/8/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) dwl_download_path or (2) dwl_include_path parameters.
ModificadaAlta (7.5)2.6%💥 ExploitKnusperleicht Quickie5/8/200616/6/2026
PHP remote file inclusion vulnerability in quickie.php in Knusperleicht Quickie, probably 0.2, allows remote attackers to execute arbitrary PHP code via a URL in the QUICK_PATH parameter.
ModificadaAlta (9.3)56%💥 ExploitMicrosoft Hyperlink Object Library19/6/200616/6/2026
Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode,…
ModificadaMedia (4.6)0.38%—Activestate Activeperl6/6/200616/6/2026
ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by creating a malicious sitecustomize.pl file in that directory. NOTE: The provenance of this information is unknown; the details are obtained…
ModificadaAlta (7.5)13%💥 ExploitPerlpodderProdder23/5/200616/6/2026
Prodder before 0.5, and perlpodder before 0.5, allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast (url attribute of an enclosure tag, or $enc_url variable), which is executed when running wget.
ModificadaMedia (5.1)4.3%—Perlpodder23/5/200616/6/2026
perlpodder before 0.5 allows remote attackers to execute arbitrary code via shell metacharacters in the URL of a podcast, which are executed when saving the URL to a log file. NOTE: the wget vector is already covered by CVE-2006-2548.
ModificadaMedia (4.3)1.9%💥 ExploitPerlcoders Group Bannerfarm20/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters.
ModificadaMedia (5)1.9%—Perlblog19/2/200616/6/2026
Directory traversal vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to read certain files via the month parameter.
ModificadaAlta (7.5)3.0%—Perlblog19/2/200616/6/2026
Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body…
ModificadaMedia (4.3)1.3%—Perlblog19/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in weblog.pl in PerlBlog 1.09b and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters.
ModificadaBaja (2.1)0.36%—Debian Libmail-audit-perl31/12/200516/6/2026
Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.
ModificadaAlta (7.2)0.40%—Larry Wall Perl16/12/200516/6/2026
Untrusted search path vulnerability in Perl before 5.8.7-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
ModificadaMedia (4.3)1.5%—Acme Labs Perlcal11/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter.
ModificadaMedia (4.6)1.4%—Perl1/12/200516/6/2026
Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using…
ModificadaMedia (4.3)1.4%—Scriptsolutions Perldiver27/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.
ModificadaMedia (4.3)1.3%—Scriptsolutions Perldiver27/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in perldiver.cgi in PerlDiver 2.x allows remote attackers to inject arbitrary web script or HTML via the module parameter.
ModificadaMedia (5)1.1%—Thesitewizard.com Chfeedback.pl Feedback Form Perl Script8/9/200516/6/2026
CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers.
ModificadaAlta (7.5)1.6%—Knusperleicht Shoutbox Script2/5/200516/6/2026
Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes.
ModificadaMedia (4.6)1.2%💥 ExploitLarry Wall Perl2/5/200516/6/2026
The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.
Orbitaley — Vulnerabilidades