Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Gazatem Technologies Gnews Publisher | 24/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in categories.asp in gNews Publisher allow remote attackers to execute arbitrary SQL commands via the (1) catID or (2) editorID parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Superfreaker Studios Upublisher | 14/11/2006 | 16/6/2026 | SQL injection vulnerability in viewarticle.asp in Superfreaker Studios UPublisher 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (9.3) | 13% | — | Microsoft AccessMicrosoft ExcelMicrosoft Excel ViewerMicrosoft Frontpage+10 | 10/10/2006 | 16/6/2026 | Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Mobilepublisherphp | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter. | |
| Modificada | Alta (9.3) | 42% | — | Microsoft OfficeMicrosoft Publisher | 12/9/2006 | 16/6/2026 | Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Mamboxchange Mambo Email Publisher | 17/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Zonemetrics Zonex Publishers Gold Edition | 9/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (9.3) | 2.9% | 💥 Exploit | Keyvan Janghorbani Epublisherpro | 11/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5.8) | 2.0% | — | Kcscripts News PublisherKcscripts Portal Pack | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Scriptsfrenzy Article Publisher PRO | 19/4/2006 | 16/6/2026 | SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter. | |
| Modificada | Baja (2.6) | 1.2% | — | Updi Network Enterprise AT1 Event Publisher | 17/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of Table field. | |
| Modificada | Media (4.3) | 1.2% | — | Upoint AT1 Event Publisher | 15/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_admin.htm and (b) eventpublisher_usersubmit.htm. | |
| Modificada | Media (5) | 1.4% | — | Upoint AT1 Event Publisher | 15/4/2006 | 16/6/2026 | UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt. | |
| Modificada | Alta (7.5) | 2.0% | — | Knowledgebasepublisher | 19/3/2006 | 16/6/2026 | PHP remote file include vulnerability in PageController.php in KnowledgebasePublisher 1.2 allows remote attackers to include and execute arbitrary PHP code via a URL in the dir parameter. | |
| Modificada | Media (4.3) | 1.3% | — | THE Media Shoppe Berhad Tmspublisher | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cfm in tmsPUBLISHER 3.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 1.6% | — | THE Media Shoppe Berhad Tmspublisher | 31/12/2005 | 16/6/2026 | _Request_Message.cfm in tmsPUBLISHER 3.3 allows remote attackers to obtain sensitive information via an invalid id argument to pagename.cfm, which reveals the installation path in an error message. | |
| Modificada | Media (5) | 1.1% | — | Nelogic Technologies Nephp Publisher | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters. | |
| Modificada | Media (4.3) | 0.94% | — | Nelogic Technologies Nephp Publisher Enterprise | 26/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in browse.php in Nephp Publisher Enterprise 3.04 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded keywords parameter. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation. | |
| Modificada | Alta (7.5) | 42% | — | Microsoft FrontpageMicrosoft OfficeMicrosoft PublisherMicrosoft Word+1 | 28/9/2004 | 16/6/2026 | Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Asksam Systems Asksam WEB Publisher | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows remote attackers to execute arbitrary script as other users via a URL. | |
| Modificada | Media (5) | 1.5% | — | Asksam Systems Asksam WEB Publisher | 31/12/2002 | 16/6/2026 | askSam Web Publisher 1.0 and 4.0 allows remote attackers to determine the full path to the web root directory via a request for a file that does not exist, which generates an error message that reveals the full path. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Gwscripts News Publisher | 20/10/2000 | 16/6/2026 | news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program. |