Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Sage-mozdev Sage | 11/1/2007 | 16/6/2026 | Firefox Sage extension 1.3.8 and earlier allows remote attackers to execute arbitrary Javascript in the local context via an RSS feed with an img tag containing the script followed by an extra trailing ">", which Sage modifies to close the img element before the malicious script. | |
| Modificada | Media (6.6) | 1.4% | — | Microsoft Message Compiler | 5/1/2007 | 16/6/2026 | Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename. NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileged program, so privilege boundaries cannot be crossed | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Scriptphp Messageriescripthp | 14/12/2006 | 16/6/2026 | SQL injection vulnerability in lire-avis.php in Messageriescripthp 2.0 allows remote attackers to execute arbitrary SQL commands via the aa parameter. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Scriptphp Messageriescripthp | 14/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Messageriescripthp 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pseudo parameter to (a) existepseudo.php, the (2) email parameter to (b) existeemail.php, or the (3) pageName or (4) cssform parameter to (c) Contact/contact.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Messagerie Locale | 28/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in centre.php in Messagerie Locale as of 20061127 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 2.2% | — | Sage | 12/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sage 1.3.6 allow remote attackers to inject arbitrary web script or HTML via JavaScript in a content:encoded element within an item element in an RSS feed, as demonstrated by four example content:encoded elements that use XMLHttpRequest to read arbitrary local… | |
| Modificada | Media (4.3) | 1.2% | — | Sage | 12/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sage allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite. | |
| Modificada | Media (5.1) | 9.9% | 💥 Exploit | XMB Software Extreme Message Board | 17/8/2006 | 16/6/2026 | Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is… | |
| Modificada | Media (5.5) | 0.29% | — | BusyboxAvaya Aura Application Enablement ServicesAvaya Aura SIP Enablement ServicesAvaya Message Networking+1 | 4/4/2006 | 16/6/2026 | BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables. | |
| Modificada | Media (4.3) | 1.2% | — | Cholod Mysql Based Message Board | 26/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Cholod Mysql Based Message Board | 26/3/2006 | 16/6/2026 | SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party… | |
| Modificada | Media (5) | 1.8% | — | Compex Netpassage Wpe54g | 2/3/2006 | 16/6/2026 | uConfig agent in Compex NetPassage WPE54G router allows remote attackers to cause a denial of service (unresposiveness) via crafted datagrams to UDP port 7778. | |
| Modificada | Media (4.3) | 1.2% | — | Starphire Technologies SitesageStarphire Technologies Sitesage-eeStarphire Technologies Sitesage-leStarphire Technologies Sitesage-sb+1 | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the norelay_highlight_words parameter. | |
| Modificada | Media (5) | 2.4% | — | Avaya Modular Messaging Message Storage Server | 22/12/2005 | 16/6/2026 | POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets. | |
| Modificada | Media (5) | 3.1% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+20 | 23/8/2005 | 16/6/2026 | Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability." | |
| Modificada | Media (4.3) | 1.4% | — | Simple Message BoardAI | 19/7/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm. | |
| Modificada | Media (5) | 6.2% | — | Sophos Anti-virusSophos MailmonitorSophos Mailmonitor FOR Notes DominoSophos Puremessage Anti-virus+1 | 19/7/2005 | 16/6/2026 | Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Mercuryboard Message Board | 21/6/2005 | 16/6/2026 | SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | |
| Modificada | Media (5) | 1.8% | — | Colored Scripts Easy Message Board | 14/5/2005 | 16/6/2026 | Directory traversal vulnerability in easymsgb.pl in Easy Message Board allows remote attackers to read arbitrary files via a .. (dot dot) in the print parameter. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Colored Scripts Easy Message Board | 14/5/2005 | 16/6/2026 | easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter. | |
| Modificada | Media (6.2) | 2.9% | 💥 Exploit | Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+16 | 14/4/2005 | 16/6/2026 | Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor. | |
| Modificada | Baja (2.1) | 0.51% | — | Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+11 | 14/4/2005 | 16/6/2026 | The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file. | |
| Modificada | Media (4.3) | 1.2% | — | Mercuryboard Message Board | 23/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MercuryBoard before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the title field of a PM (private message). | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 9/2/2005 | 16/6/2026 | Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. |