Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 62% | 💥 Exploit | Limesurvey | 10/7/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5)… | |
| Modificada | Media (6.8) | 3.2% | 💥 Exploit | Opensurveypilot | 22/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathToProjectAdmin parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Fisasp.com Ultimate Survey PRO | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.asp in Ultimate Survey Pro allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) did parameter. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Phpsurveyor | 27/4/2006 | 16/6/2026 | SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then… | |
| Modificada | Alta (7.5) | 2.1% | — | Philip Loftin Aspsurvey | 13/1/2006 | 16/6/2026 | SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp. | |
| Modificada | Media (4.6) | 0.59% | — | Autodesk 3DS MAXAutodesk Architectural DesktopAutodesk AutocadAutodesk Autocad Civil 3D+14 | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329. | |
| Modificada | Alta (7.5) | 1.4% | — | Phpsurveyor | 30/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHPSurveyor before 0.991 allow remote attackers to execute arbitrary SQL commands via the (1) sql parameter in browse.php and the (2) sid, (3) lid, (4) gid, and (5) token parameters in certain PHP scripts. | |
| Modificada | Alta (7.5) | 1.2% | — | PHP Labs Survey Wizard | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | PHP Surveyor | 27/7/2005 | 16/6/2026 | PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php. | |
| Modificada | Alta (7.5) | 2.9% | — | PHP Surveyor | 27/7/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8)… | |
| Modificada | Media (5) | 1.2% | — | PHP Surveyor | 26/7/2005 | 16/6/2026 | PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to… | |
| Modificada | Media (5) | 1.0% | — | PHP Surveyor | 26/7/2005 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or the sid parameter to (4) dataentry.php or (5) export.php. | |
| Modificada | Media (4.3) | 1.2% | — | Joel Palmius MOD Survey | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings. | |
| Modificada | Media (5) | 1.4% | — | MOD Survey | 31/12/2003 | 16/6/2026 | mod_survey 3.0.0 through 3.0.15-pre6 does not check whether a survey exists before creating a subdirectory for it, which allows remote attackers to cause a denial of service (disk consumption and possible crash). | |
| Modificada | Media (5) | 2.4% | — | Php-survey | 18/6/2002 | 16/6/2026 | PHP-Survey 20000615 and earlier stores the global.inc file under the web root, which allows remote attackers to obtain sensitive information, including database credentials, if .inc files are not preprocessed by the server. | |
| Modificada | Alta (10) | 4.0% | — | Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+11 | 12/3/2001 | 16/6/2026 | Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. | |
| Modificada | Alta (10) | 4.5% | — | BnbsurveyAI | 3/12/1998 | 16/6/2026 | BNBSurvey survey.cgi program allows remote attackers to execute commands via shell metacharacters. | |
| Modificada | Alta (7.5) | 9.1% | 💥 Exploit | Renaud Deraison Faxsurvey | 4/8/1998 | 16/6/2026 | Hylafax faxsurvey CGI script on Linux allows remote attackers to execute arbitrary commands via shell metacharacters in the query string. |