Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Solarwinds Backup ProfilerSolarwinds Storage ManagerSolarwinds Storage Profiler | 20/12/2017 | 16/6/2026 | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field. | |
| Modificada | Media (6.1) | 1.2% | — | Cozmoslabs Profile Builder | 6/10/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url parameter. | |
| Modificada | Media (6.1) | 0.89% | — | Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+47 | 22/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,… | |
| Modificada | Media (5.3) | 1.6% | — | Miniprofiler Rack-mini-profiler | 2/5/2017 | 17/6/2026 | The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks. | |
| Modificada | Media (4.3) | 1.1% | — | UC Profile Project UC Profile | 17/11/2015 | 17/6/2026 | The UC Profile module 6.x-1.x before 6.x-1.3 for Drupal does not properly check access to profiles in certain circumstances, which might allow remote attackers to obtain sensitive information from the anonymous user profile via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | — | HP Smart Profile Server Data Analytics Layer | 18/10/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.95% | — | Profile2 Privacy Project Profile2 Privacy | 15/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Profile2 Privacy module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer Profile2 Privacy Levels" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | SAP Profile Maintenance | 30/4/2014 | 17/6/2026 | SAP Profile Maintenance does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Telepresence TC SoftwareCisco IP Video Phone E20Cisco Telepresence Codec C40Cisco Telepresence Codec C60+10 | 21/6/2013 | 16/6/2026 | Cisco TelePresence TC Software before 5.1.7 and TE Software before 4.1.3 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCue01743. | |
| Modificada | Media (6.3) | 0.40% | — | Maynard Johnson Oprofile | 9/6/2011 | 16/6/2026 | The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in conjunction with a symlink attack on the opd_pipe file, a different vulnerability than CVE-2011-1760. | |
| Modificada | Media (6.3) | 0.54% | — | Maynard Johnson Oprofile | 9/6/2011 | 16/6/2026 | Directory traversal vulnerability in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to overwrite arbitrary files via a .. (dot dot) in the --save argument, related to the --session-dir argument, a different vulnerability than CVE-2011-1760. | |
| Modificada | Alta (7.2) | 0.48% | — | Maynard Johnson Oprofile | 9/6/2011 | 16/6/2026 | utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session-dir, or (3) --xen argument, related to the daemonrc file and the do_save_setup and do_load_setup functions, a different vulnerability than CVE-2011-1760. | |
| Modificada | Alta (7.2) | 1.4% | 💥 Exploit | Maynard Johnson Oprofile | 9/6/2011 | 16/6/2026 | utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to conduct eval injection attacks and gain privileges via shell metacharacters in the -e argument. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Interlogy Profile Manager | 28/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to execute arbitrary SQL commands via a pmadm cookie in (1) an edittemp action or (2) a users action. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | V3chat V3 Chat Profiles Dating Script | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | V3chat V3 Chat Profiles Dating Script | 31/12/2008 | 16/6/2026 | V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | E107 Alternate Profiles Plugin | 29/10/2008 | 16/6/2026 | SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM ComprofilerJoomlapolis Community BuilderMambo COM Comprofiler | 6/5/2008 | 16/6/2026 | SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php. | |
| Modificada | Media (6.8) | 21% | 💥 Exploit | Phpprofiles | 27/2/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomla COM ProfileMambo COM Profile | 20/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Profilecms | 20/11/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) codes action in the profile-codes module, (2) videos action in the video-codes module, or (3) games action in the arcade-games module. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Profilecms | 30/10/2007 | 16/6/2026 | Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving creation of a profile. | |
| Modificada | Media (6.8) | 1.2% | — | Phpmyprofiler | 26/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include/plugin/block.t.php in Peter Schmidt phpmyProfiler 0.9.6b allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. NOTE: this issue is disputed by CVE because the applicable require_once is in a function that is not called on a… | |
| Modificada | Media (4.6) | 0.32% | — | Phpprofiles | 26/12/2006 | 16/6/2026 | phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php. | |
| Modificada | Alta (7.5) | 9.5% | 💥 Exploit | Phpprofiles | 26/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the menu parameter to (1) include/body.inc.php or (2) include/body_admin.inc.php; or a URL in the incpath parameter to (3) index.inc.php, (4) account.inc.php, (5)… |