Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.8%—NEO Japan Desknets27/10/200616/6/2026
Buffer overflow in Desknet's (niokeru) before 5.0J R1.0 might allow remote authenticated users to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.8%—Oneorzero Helpdesk24/10/200616/6/2026
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
ModificadaAlta (7.5)8.0%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.
ModificadaMedia (6.8)4.8%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field.
ModificadaAlta (7.5)8.0%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter.
ModificadaAlta (7.5)2.6%—Neosys Neon Webmail23/9/200616/6/2026
Neon WebMail for Java before 5.08 allows remote attackers to execute arbitrary Java (JSP) code by sending an e-mail message with a JSP file attachment, which is stored under the web root with a predictable filename.
ModificadaMedia (5)8.1%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters.
ModificadaAlta (7.5)3.8%💥 ExploitNeosys Neon Webmail23/9/200616/6/2026
Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortkey_desc parameters in the (b) maillist servlet.
ModificadaMedia (6.8)1.2%—Oneorzero24/8/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)1.2%—Oneorzero24/8/200616/6/2026
SQL injection vulnerability in index.php in OneOrZero 1.6.4.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.4%—Neocrome Seditio30/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer field.
ModificadaMedia (5)1.5%—Northern Solutions Xeneo WEB Server9/5/200616/6/2026
Xeneo Web Server 2.2.22.0 allows remote attackers to obtain the source code of script files via crafted requests containing dot, space, and slash characters in the file extension.
ModificadaMedia (4.3)1.9%💥 ExploitNeomail2/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.
ModificadaMedia (5)1.4%—Neocrome Land Down Under29/4/200616/6/2026
plug.php in Land Down Under (LDU) 802 and earlier allows remote attackers to obtain sensitive information via an invalid (1) month or (2) year parameter, which reveals the path in an error message.
ModificadaMedia (5)3.8%💥 ExploitNeon Software Neon Responder20/4/200616/6/2026
Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation.
ModificadaAlta (7.5)1.3%💥 ExploitOneorzero30/3/200616/6/2026
SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.
ModificadaAlta (7.5)1.8%—Zoneo-soft Freeforum2/3/200616/6/2026
Direct static code injection vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to execute arbitrary PHP code via the (1) X-Forwarded-For and (2) Client-Ip HTTP headers, which are stored in Data/flood.db.php.
ModificadaMedia (4.3)1.4%—Zoneo-soft Freeforum2/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in func.inc.php in ZoneO-Soft freeForum before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) subject parameters.
ModificadaMedia (5)1.5%—Neomail15/2/200616/6/2026
The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, which allows remote attackers to add and delete arbitrary files, when configured with homedirfolders and homedirspools disabled.
ModificadaMedia (4.3)1.9%—Neomail4/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.27 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. NOTE: some sources say that the affected parameter is "date," but the demonstration URL shows that it is "sort".
ModificadaMedia (6.8)1.1%—Neocrome Land Down UnderAI31/12/200516/6/2026
SQL injection vulnerability in Neocrome Land Down Under (LDU) 801 allows remote attackers to execute arbitrary SQL commands via an HTTP Referer header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)2.3%💥 ExploitNeocrome Land Down Under31/12/200516/6/2026
Multiple SQL injection vulnerabilities in Land Down Under (LDU) v801 and earlier allow remote attackers to execute arbitrary SQL commands via parameters including (1) the m parameter in auth.php, (2) the f parameter in events.php, or (3) the e parameter in plug.php.
ModificadaMedia (5)1.2%—Michael Scholz Contineo31/12/200516/6/2026
Michael Scholz and Sebastian Stein Contineo 2.0, when the admin account lacks an e-mail address attribute, displays the password hash in a warning upon page reload, which might allow remote attackers to view the hash.
ModificadaAlta (7.5)1.2%💥 ExploitZoneo-soft Freeforum26/11/200516/6/2026
Multiple SQL injection vulnerabilities in forum.php in freeForum 1.1 and earlier and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter or (2) thread parameter in thread mode.
ModificadaMedia (4.3)1.3%—Neocrome Land Down Under14/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in events.php in Land Down Under (LDU) 801 and earlier allows remote attackers to inject arbitrary web script or HTML via the Description field in an event.
Orbitaley — Vulnerabilidades