Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Dnnsoftware Dotnetnuke | 27/8/2009 | 16/6/2026 | Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessing the install wizard page via unknown vectors. | |
| Modificada | Media (6.5) | 1.2% | — | Dnnsoftware Dotnetnuke | 27/8/2009 | 16/6/2026 | Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity." | |
| Modificada | Media (6.8) | 1.2% | — | Dotproject | 23/4/2009 | 16/6/2026 | dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.0% | — | Dnnsoftware Dotnetnuke | 22/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality." | |
| Modificada | Media (4.3) | 1.1% | — | Dnnsoftware Dotnetnuke | 21/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote attackers to inject arbitrary web script or HTML via the querystring parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Dnnsoftware Dotnetnuke | 21/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths." | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Dnnsoftware Dotnetnuke | 7/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Dotcontent Fluentcms | 7/4/2009 | 16/6/2026 | SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL commands via the sid parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.6) | 1.6% | — | Dnnsoftware Dotnetnuke | 30/3/2009 | 16/6/2026 | Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files. | |
| Modificada | Media (6.8) | 1.00% | — | Dnnsoftware Dotnetnuke | 30/3/2009 | 16/6/2026 | Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors. | |
| Modificada | Media (5.1) | 2.5% | 💥 Exploit | Dnnsoftware Dotnetnuke | 30/3/2009 | 16/6/2026 | DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys. | |
| Modificada | Media (4.3) | 1.1% | — | Dotclear | 17/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the administrative interface in Dotclear before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Dotnetblogengine Blogengine.net | 16/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (6.4) | 1.9% | — | Dnnsoftware Dotnetnuke | 5/3/2009 | 16/6/2026 | Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Dotnetindex Ikon Admanager | 16/12/2008 | 16/6/2026 | Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for ikonBAnner_AdManager.mdb. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Dotnetindex Professional Download Assistant | 15/12/2008 | 16/6/2026 | Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Dotnetindex Professional Download Assistant | 15/12/2008 | 16/6/2026 | SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6) | 0.93% | — | Dotproject | 2/9/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in a viewuser action. | |
| Modificada | Media (4.3) | 1.1% | — | Dotproject | 2/9/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2) the date parameter in a calendar day_view action, (3) the callback parameter in a public calendar action, or (4) the… | |
| Modificada | Media (4.3) | 4.6% | 💥 Exploit | Dotcms | 19/8/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot. | |
| Modificada | Alta (9.3) | 4.6% | — | Dotclear | 18/7/2008 | 16/6/2026 | Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images. | |
| Modificada | Media (4.3) | 1.0% | — | Dotcms | 21/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 7.5% | 💥 Exploit | Reddot CMS | 22/4/2008 | 16/6/2026 | SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and 7.0, allows remote attackers to execute arbitrary SQL commands via the LngId parameter. | |
| Modificada | Media (6.4) | 1.2% | — | Dotproject | 16/10/2007 | 16/6/2026 | dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via a crafted URL. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (2.6) | 1.3% | — | Dotclear | 11/7/2007 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in DotClear 1.2.6 allow remote attackers to perform actions as arbitrary users via the (1) tool_url parameter to ecrire/tools.php and multiple fields on the (2) blogconf, (3) blogroll, (4) ecrire/redacteur.php, and (5) ecrire/user_prefs.php pages. |