Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Cce-interact Interact | 30/7/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) module and (2) file parameters. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Interact | 14/5/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[LANGUAGE_CPATH] parameter to modules/forum/embedforum.php and the (2) CONFIG[BASE_PATH]… | |
| Modificada | Media (4.3) | 1.0% | — | TOR World COM VoteTOR World I-navigatorTOR World Interactive BBSTOR World Mobile Frontier+6 | 22/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and… | |
| Modificada | Alta (7.8) | 1.5% | — | BEA Systems Aqualogic InteractionBEA Systems Plumtree Collaboration | 22/2/2008 | 16/6/2026 | Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL. | |
| Modificada | Media (4.3) | 1.2% | — | BEA Systems Aqualogic InteractionBEA Systems Plumtree Foundation | 21/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | BEA Aqualogic Interaction | 1/12/2007 | 16/6/2026 | portal/server.pt in the Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows wildcards in advanced searches for usernames, which allows remote attackers to enumerate valid usernames via the in_tx_fulltext parameter. | |
| Modificada | Media (5) | 1.6% | — | BEA Aqualogic Interaction | 1/12/2007 | 16/6/2026 | The Plumtree portal in BEA AquaLogic Interaction 5.0.2 through 5.0.4 and 6.0.1.218452 allows remote attackers to obtain version numbers and internal hostnames by reading comments in the HTML source of any page. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Omnistar Interactive Omnistar Live | 30/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Omnistar Live allow remote attackers to inject arbitrary web script or HTML via (1) the category_id parameter to users/kb.php, and possibly (3) the Email Box field in profile.php. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Omnistar Interactive Omnistar Article Manager | 18/9/2007 | 16/6/2026 | SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917. | |
| Modificada | Media (6.8) | 6.0% | 💥 Exploit | Rebellion Rogue TrooperRival Interactive Prism | 23/8/2007 | 16/6/2026 | Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query. | |
| Modificada | Media (4.3) | 1.2% | — | Interact | 8/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Interact before 2.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2007-3328. | |
| Modificada | Alta (9.3) | 8.2% | — | Interactual Technologies Interactual PlayerRoxio Cineplayer | 17/7/2007 | 16/6/2026 | Multiple stack-based buffer overflows in (a) InterActual Player 2.60.12.0717 and (b) Roxio CinePlayer 3.2 allow remote attackers to execute arbitrary code via a (1) long FailURL attribute in the IAMCE ActiveX Control (IAMCE.dll) or a (2) long URLCode attribute in the IAKey ActiveX Control (IAKey.dll). NOTE: the… | |
| Modificada | Media (4.3) | 2.3% | — | Interact | 21/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Interact 2.4 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) module_key parameter to (a) kb/kb.php, (b) quiz/runquiz.php, (c) quiz/quiz.php, (d) forum/forum.php, (e) forum/byname.php, and (f) journal/journalview.php in modules/,… | |
| Modificada | Alta (9.3) | 35% | 💥 Exploit | Interactual Technologies Interactual PlayerIntervideo WindvdRoxio Cineplayer | 21/3/2007 | 16/6/2026 | Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio CinePlayer 3.2, (3) WinDVD 7.0.27.172, and possibly other products, allows remote attackers to execute arbitrary code via a long ApplicationType property. | |
| Modificada | Alta (9.3) | 37% | — | Microsoft Step-by-step Interactive Training | 13/2/2007 | 16/6/2026 | Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Interactive-scripts.com PHP Membership Manager | 30/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Omnistar Interactive Omnistar Article Manager | 15/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in OmniStar Article Manager allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in (a) articles/comments.php and (b) articles/article.php, and the (2) page_id parameter in (c) articles/pages.php. | |
| Modificada | Media (5) | 1.4% | — | Xiao Gang WWW Interactive Mathematics Server | 23/10/2006 | 16/6/2026 | Unspecified vulnerability in XIAO Gang WWW Interactive Mathematics Server (WIMS) before 3.60 allows remote attackers to modify unspecified data via unspecified vectors involving "variable rights." | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Kinesis Interactive Cinema System | 23/10/2006 | 16/6/2026 | SQL injection vulnerability in index.asp in Kinesis Interactive Cinema System (KICS) CMS allows remote attackers to execute arbitrary SQL commands via the (1) txtUsername (user) or (2) txtPassword (pass) parameters. | |
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | Interact Learning Community Environment Interact | 30/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b) includes/common.inc.php, and the (2) CONFIG[LANGUAGE_CPATH] parameter in (c)… | |
| Modificada | Media (6.8) | 1.6% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in add_url.php in CloudNine Interactive Links Manager 2006-06-12 allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, or (3) keywords parameters. | |
| Modificada | Media (5.1) | 1.3% | — | Cloudnine Interactive Links Manager | 24/8/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter. | |
| Modificada | Media (6.4) | 2.8% | — | Interactual Technologies Interactual Player | 28/7/2006 | 16/6/2026 | Stack-based buffer overflow in ITIRecorder.MicRecorder ActiveX control in iarecord.dll in InterActual Player before 2.6 allows remote attackers to execute arbitrary code via a long argument to the Files method. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5.1) | 6.8% | 💥 Exploit | Facile Interactive WEB | 1/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) pathfile parameter in (a) p-editpage.php and (b) p-editbox.php, and the (2) mytheme and (3) myskin parameters in… | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Facile Interactive WEB | 1/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d)… |