Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Openconcept Back-end CMS | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End CMS 0.4.7 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter to (1) click.php or (2) pollcollector.php in htdocs/; or (3) index.php, (4) articlepages.php, (5) articles.php, (6) articleform.php, (7)… | |
| Modificada | Media (6.8) | 1.1% | — | Openconcept Back-end CMS | 18/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in htdocs/php.php in OpenConcept Back-End CMS 0.4.7 allows remote attackers to inject arbitrary web script or HTML via the page[] parameter. | |
| Modificada | Alta (9.4) | 3.1% | 💥 Exploit | Barekoncept Pheap | 2/3/2007 | 16/6/2026 | Directory traversal vulnerability in edit.php in pheap allows remote attackers to read and modify arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Scriptphp Annoncescripthp | 12/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) email.php, the (2) no parameter in (b) voirannonce.php, the (3) idmembre parameter in (c) admin/admin_membre/fiche_membre.php, and the (4) idannonce parameter in (d)… | |
| Modificada | Media (5) | 1.3% | — | Scriptphp Annoncescripthp | 12/12/2006 | 16/6/2026 | admin/admin_membre/fiche_membre.php in AnnonceScriptHP 2.0 allows remote attackers to obtain sensitive information via the idmembre parameter, which discloses the passwords for arbitrary users. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Scriptphp Annoncescripthp | 12/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AnnonceScriptHP 2.0 allow remote attackers to inject arbitrary web script or HTML via the email parameter in (1) erreurinscription.php, (2) Templates/admin.dwt.php, (3) Templates/commun.dwt.php, (4) membre.dwt.php, and (5) admin/admin_config/Aide.php. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Comscripts Annoncev | 7/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Bare Concept Media Pheap CMS | 7/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The lib/config.php vector is… | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Bare Concept Media Pheap CMS | 1/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. | |
| Modificada | Media (5) | 12% | — | Cisco VPN 3000 Concentrator Series Software | 23/8/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Cisco VPN 3000 series concentrators before 4.1, 4.1.x up to 4.1(7)L, and 4.7.x up to 4.7(2)F allow attackers to execute the (1) CWD, (2) MKD, (3) CDUP, (4) RNFR, (5) SIZE, and (6) RMD FTP commands to modify files or create and delete directories via unknown vectors. | |
| Modificada | Media (5) | 6.9% | — | Cisco IOSCisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 Concentrator+17 | 27/7/2006 | 16/6/2026 | Internet Key Exchange (IKE) version 1 protocol, as implemented on Cisco IOS, VPN 3000 Concentrators, and PIX firewalls, allows remote attackers to cause a denial of service (resource exhaustion) via a flood of IKE Phase-1 packets that exceed the session expiration rate. NOTE: it has been argued that this is due to a… | |
| Modificada | Media (5.1) | 1.7% | — | Planet Concept Planetgallery | 24/7/2006 | 16/6/2026 | admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types. | |
| Modificada | Alta (10) | 6.2% | — | Planet Concept Planetnews | 13/7/2006 | 16/6/2026 | PlaNet Concept planetNews allows remote attackers to bypass authentication and execute arbitrary code via a direct request to news/admin/planetnews.php. | |
| Modificada | Baja (2.6) | 1.7% | — | Cisco ASA 5500Cisco VPN 3000 Concentrator Series Software | 19/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WebVPN feature in the Cisco VPN 3000 Series Concentrators and Cisco ASA 5500 Series Adaptive Security Appliances (ASA), when in WebVPN clientless mode, allow remote attackers to inject arbitrary web script or HTML via the domain parameter in (1) dnserror.html… | |
| Modificada | Alta (7.5) | 1.5% | — | Planet Concept Planetstat | 12/5/2006 | 16/6/2026 | PlaNet Concept plaNetStat 20050127 allows remote attackers to gain administrative privileges, and view and configure log files, via a direct request to the (1) admin.php or (2) settings.php page. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Planet Concept Planetgallery | 1/5/2006 | 16/6/2026 | planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Planet Concept Planetsearch+ | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter. | |
| Modificada | Alta (7.8) | 3.2% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3030 Concentator | 31/1/2006 | 16/6/2026 | Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet. | |
| Modificada | Media (4.3) | 1.2% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts Dev Hound 2.24 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple unspecified user input fields. | |
| Modificada | Media (5) | 1.4% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Nexus Concepts Dev Hound 2.24 and earlier allows remote attackers to obtain the installation path via a URL containing a non-existent .dll file. | |
| Modificada | Media (4.6) | 0.34% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Nexus Concepts Dev Hound 2.24 and earlier stores username and password information in cleartext in the devhound.tdbd file, which allows local users to gain privileges. | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+17 | 22/12/2005 | 16/6/2026 | The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Binary-concepts Binary Board System | 17/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) inreplyto, (2) article, and (3) board parameters to reply.pl, (4) branch, (5) board, and (6) stats.pl parameters to (b) stats.pl, and (7) board… | |
| Modificada | Media (5) | 5.2% | — | Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+4 | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details… | |
| Modificada | Media (5) | 2.3% | — | Cisco VPN 3000 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+4 | 20/6/2005 | 16/6/2026 | Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname. |