Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.6% | — | Squishdot | 15/2/2006 | 16/6/2026 | mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, which allows remote attackers to bypass spam filters by injecting SMTP headers, probably due to a CRLF injection vulnerability. | |
| Modificada | Alta (9) | 1.8% | — | Metadot Portal Server | 21/12/2005 | 16/6/2026 | Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Dotclear | 2/12/2005 | 16/6/2026 | SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie. | |
| Modificada | Alta (10) | 1.6% | — | Dotclear | 1/12/2005 | 16/6/2026 | Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Dotnetindex Active News Manager | 31/5/2005 | 16/6/2026 | SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password. | |
| Modificada | Media (4.3) | 1.3% | — | Dnnsoftware Dotnetnuke | 19/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log. | |
| Modificada | Media (4.3) | 1.2% | — | Dnnsoftware Dotnetnuke | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Alta (7.5) | 1.2% | — | Dnnsoftware Dotnetnuke | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter. | |
| Modificada | Media (5) | 1.4% | — | Dnnsoftware Dotnetnuke | 31/12/2004 | 16/6/2026 | DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter. | |
| Modificada | Alta (9) | 1.7% | — | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx. | |
| Modificada | Alta (7.5) | 1.4% | — | Dotbr Botbr | 31/12/2003 | 16/6/2026 | DotBr 0.1 stores config.inc with insufficient access control under the web document root, which allows remote attackers to obtain sensitive information such as SQL usernames and passwords. | |
| Modificada | Alta (7.5) | 1.5% | — | Dotbr Botbr | 31/12/2003 | 16/6/2026 | foo.php3 in DotBr 0.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Dotbr Botbr | 31/12/2003 | 16/6/2026 | DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) system.php3. | |
| Modificada | Media (4.3) | 1.1% | — | Onedotoh Simple File Manager | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names. | |
| Modificada | Alta (10) | 5.5% | 💥 Exploit | Dotproject | 11/4/2003 | 16/6/2026 | index.php in dotProject 0.2.1.5 allows remote attackers to bypass authentication via a cookie or URL with the user_cookie parameter set to 1. |