Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
349 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.31% | — | Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client | 22/2/2007 | 16/6/2026 | Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain… | |
| Modificada | Alta (7.5) | 1.5% | — | Distributed Checksum Clearinghouse DCC | 21/2/2007 | 16/6/2026 | Unspecified vulnerability in Distributed Checksum Clearinghouse (DCC) before 1.3.51 allows remote attackers to delete or add hosts in /var/dcc/maps. | |
| Modificada | Media (6.8) | 1.3% | — | Salims Softhouse JAF CMS | 3/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) the message parameter, and possibly other parameters, in module/shout/jafshout.php (aka the shoutbox); and (2) the message body in a forum post… | |
| Modificada | Alta (7.5) | 2.6% | — | Salims Softhouse JAF CMS | 3/10/2006 | 16/6/2026 | module/shout/jafshout.php (aka the shoutbox) in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allows remote attackers to execute arbitrary code within sections bounded by "<?php" and "?>", possibly due to a static code injection vulnerability involving admin/data_inc.php. | |
| Modificada | Media (6.8) | 1.1% | — | Salims Softhouse JAF CMS | 3/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) url, (3) title, and (4) about parameters in a forum post. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Alta (7.5) | 2.0% | — | Bluehouse Project Phptrader | 22/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpTRADER 4.9 SP5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sectio parameter in (a) login.php, (b) write_newad.php, (c) newad.php, (d) printad.php, (e) askseller.php, (f) browse.php, (g) showmemberads.php, (h) note_ad.php, (i) abuse.php,… | |
| Modificada | Media (4.3) | 1.8% | — | JAM Warehouse Knowledgetree Open Source | 7/6/2006 | 16/6/2026 | view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS. | |
| Modificada | Media (6.4) | 7.5% | 💥 Exploit | Lighthouse Development Squirrelcart | 19/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter. | |
| Modificada | Media (6.4) | 1.3% | — | Inhouse Associates Ia-calendar | 10/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in IA-Calendar allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in (a) calendar_new.asp and (b) default.asp, and (2) ID parameter in (c) calendar_detail.asp. NOTE: the provenance of this information is unknown; the details are obtained from… | |
| Modificada | Media (5.8) | 1.2% | — | Inhouse Associates Ia-calendar | 10/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar_new.asp in IA-Calendar allows remote attackers to inject arbitrary web script or HTML via the TypeName1 parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5.8) | 1.5% | 💥 Exploit | Smartwin Technology Cyberoffice Warehouse Builder | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Smartwin Technology Cyberoffice Warehouse Builder | 4/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm. | |
| Modificada | Baja (3.7) | 3.7% | 💥 Exploit | Fidra Lighthouse CMSAI | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology.… | |
| Modificada | Media (5) | 1.7% | — | Salims Softhouse JAF CMS | 28/6/2005 | 16/6/2026 | Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the path in an error message. NOTE: a followup suggests that this may… | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Active WEB Softwares Active Auction House | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Lighthouse Development Squirrelcart | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Active WEB Softwares Active Auction House | 6/4/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp. | |
| Modificada | Alta (7.5) | 2.0% | — | Salims Softhouse JAF CMS | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter. | |
| Modificada | Media (5) | 1.6% | — | Salims Softhouse JAF CMS | 31/12/2004 | 16/6/2026 | The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php. | |
| Modificada | Alta (7.5) | 2.6% | — | Trend Micro Damage Cleanup ServerTrend Micro Housecall | 27/8/2003 | 16/6/2026 | Multiple buffer overflows in ActiveX controls used by Trend Micro HouseCall 5.5 and 5.7, and Damage Cleanup Server 1.0, allow remote attackers to execute arbitrary code via long parameter strings. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Mediahouse Software Statistics Server Livestats | 20/10/2000 | 16/6/2026 | Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request. | |
| Modificada | Alta (10) | 3.8% | — | Ithouse Mail Server | 30/5/2000 | 16/6/2026 | Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command. | |
| Modificada | Alta (7.2) | 0.84% | — | Mediahouse Software Statistics Server | 30/9/1999 | 16/6/2026 | Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | Mediahouse Software Statistics Server | 30/9/1999 | 16/6/2026 | Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands. |