Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.31%—Cisco Secure Services ClientCisco Security AgentCisco Trust AgentMeetinghouse Aegis Secureconnect Client22/2/200716/6/2026
Cisco Secure Services Client (CSSC) 4.x, Trust Agent 1.x and 2.x, Cisco Security Agent (CSA) 5.0 and 5.1 (when a vulnerable Trust Agent has been deployed), and the Meetinghouse AEGIS SecureConnect Client do not drop privileges when the help facility in the supplicant GUI is invoked, which allows local users to gain…
ModificadaAlta (7.5)1.5%—Distributed Checksum Clearinghouse DCC21/2/200716/6/2026
Unspecified vulnerability in Distributed Checksum Clearinghouse (DCC) before 1.3.51 allows remote attackers to delete or add hosts in /var/dcc/maps.
ModificadaMedia (6.8)1.3%—Salims Softhouse JAF CMS3/10/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) the message parameter, and possibly other parameters, in module/shout/jafshout.php (aka the shoutbox); and (2) the message body in a forum post…
ModificadaAlta (7.5)2.6%—Salims Softhouse JAF CMS3/10/200616/6/2026
module/shout/jafshout.php (aka the shoutbox) in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allows remote attackers to execute arbitrary code within sections bounded by "<?php" and "?>", possibly due to a static code injection vulnerability involving admin/data_inc.php.
ModificadaMedia (6.8)1.1%—Salims Softhouse JAF CMS3/10/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) url, (3) title, and (4) about parameters in a forum post. NOTE: the provenance of this information is unknown; the details are…
ModificadaAlta (7.5)2.0%—Bluehouse Project Phptrader22/6/200616/6/2026
Multiple SQL injection vulnerabilities in phpTRADER 4.9 SP5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sectio parameter in (a) login.php, (b) write_newad.php, (c) newad.php, (d) printad.php, (e) askseller.php, (f) browse.php, (g) showmemberads.php, (h) note_ad.php, (i) abuse.php,…
ModificadaMedia (4.3)1.8%—JAM Warehouse Knowledgetree Open Source7/6/200616/6/2026
view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS.
ModificadaMedia (6.4)7.5%💥 ExploitLighthouse Development Squirrelcart19/5/200616/6/2026
PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter.
ModificadaMedia (6.4)1.3%—Inhouse Associates Ia-calendar10/5/200616/6/2026
Multiple SQL injection vulnerabilities in IA-Calendar allow remote attackers to execute arbitrary SQL commands via the (1) type parameter in (a) calendar_new.asp and (b) default.asp, and (2) ID parameter in (c) calendar_detail.asp. NOTE: the provenance of this information is unknown; the details are obtained from…
ModificadaMedia (5.8)1.2%—Inhouse Associates Ia-calendar10/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in calendar_new.asp in IA-Calendar allows remote attackers to inject arbitrary web script or HTML via the TypeName1 parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (5.8)1.5%💥 ExploitSmartwin Technology Cyberoffice Warehouse Builder4/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2…
ModificadaAlta (7.5)2.7%💥 ExploitSmartwin Technology Cyberoffice Warehouse Builder4/5/200616/6/2026
Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.
ModificadaBaja (3.7)3.7%💥 ExploitFidra Lighthouse CMSAI31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Lighthouse does not in any way make use of the PHP technology.…
ModificadaMedia (5)1.7%—Salims Softhouse JAF CMS28/6/200516/6/2026
Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the path in an error message. NOTE: a followup suggests that this may…
ModificadaMedia (4.3)5.1%💥 ExploitActive WEB Softwares Active Auction House2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Active Auction House allow remote attackers to inject arbitrary web script or HTML via the (1) ReturnURL, (2) password, (3) username parameter, (4) ReturnURL parameter to account.asp, (5) Table, (6) Title parameter to sendpassword.asp, or (7) itemid to…
ModificadaAlta (7.5)1.2%💥 ExploitLighthouse Development Squirrelcart2/5/200516/6/2026
SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action.
ModificadaAlta (7.5)4.3%💥 ExploitActive WEB Softwares Active Auction House6/4/200516/6/2026
Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp.
ModificadaAlta (7.5)2.0%—Salims Softhouse JAF CMS31/12/200416/6/2026
Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot dot) in the show parameter.
ModificadaMedia (5)1.6%—Salims Softhouse JAF CMS31/12/200416/6/2026
The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals the installation path in an error message, as demonstrated using index.php.
ModificadaAlta (7.5)2.6%—Trend Micro Damage Cleanup ServerTrend Micro Housecall27/8/200316/6/2026
Multiple buffer overflows in ActiveX controls used by Trend Micro HouseCall 5.5 and 5.7, and Damage Cleanup Server 1.0, allow remote attackers to execute arbitrary code via long parameter strings.
ModificadaAlta (7.5)3.7%💥 ExploitMediahouse Software Statistics Server Livestats20/10/200016/6/2026
Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.
ModificadaAlta (10)3.8%—Ithouse Mail Server30/5/200016/6/2026
Buffer overflow in ITHouse mail server 1.04 allows remote attackers to execute arbitrary commands via a long RCPT TO mail command.
ModificadaAlta (7.2)0.84%—Mediahouse Software Statistics Server30/9/199916/6/2026
Mediahouse Statistics Server allows remote attackers to read the administrator password, which is stored in cleartext in the ss.cfg file.
ModificadaMedia (5)7.0%💥 ExploitMediahouse Software Statistics Server30/9/199916/6/2026
Buffer overflow in Mediahouse Statistics Server allows remote attackers to execute commands.
Orbitaley — Vulnerabilidades