Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.4% | — | Modxcms Evolution | 2/2/2011 | 16/6/2026 | Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE-2010-1427. | |
| Modificada | Alta (7.5) | 1.7% | — | Modxcms Evolution | 2/2/2011 | 16/6/2026 | SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch. | |
| Modificada | Media (4.3) | 1.6% | — | Modxcms Evolution | 15/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to AjaxSearch. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Fullrevolution Aspwebalbum | 19/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in pics/, related to the uploadmedia action in album.asp. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Fullrevolution Aspwebalbum | 19/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a summary action. | |
| Modificada | Alta (7.5) | 1.1% | — | B2evolution Starrating Plugin | 18/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.44% | — | Gnome Evolution | 14/5/2009 | 16/6/2026 | The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files. | |
| Modificada | Media (4.3) | 1.0% | — | Evolution-extreme Nuke Evolution Xtreme | 28/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 1.1% | — | Fullrevolution Aspwebcalendar | 2/4/2009 | 16/6/2026 | aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb. | |
| Modificada | Alta (7.5) | 3.3% | — | Go-evolution Evolution-data-server | 14/3/2009 | 16/6/2026 | Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel. | |
| Modificada | Media (5.8) | 2.3% | — | Gnome Evolution-data-server | 14/3/2009 | 16/6/2026 | The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a… | |
| Modificada | Media (5) | 2.2% | — | Evolution | 12/2/2009 | 16/6/2026 | Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Fullrevolution Aspwebcalendar2008 | 24/6/2008 | 16/6/2026 | Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/. | |
| Modificada | Alta (9.3) | 5.7% | — | Gnome Evolution | 4/6/2008 | 16/6/2026 | Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window). | |
| Modificada | Alta (7.6) | 5.7% | — | Gnome Evolution | 4/6/2008 | 16/6/2026 | Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment. | |
| Modificada | Media (6.8) | 6.0% | — | Gnome Evolution | 6/3/2008 | 16/6/2026 | Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field. | |
| Modificada | Alta (7.8) | 2.3% | 💥 Exploit | Tumusika Evolution | 4/12/2007 | 16/6/2026 | TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Tumusika Evolution | 30/11/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) languages_n.php, (2) languages_f.php, or (3) languages.php in inc/; and (4) allow remote attackers to read arbitrary local… | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | ROI Revolution Urchin | 26/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, a different vulnerability than CVE-2007-4713. NOTE: this can be leveraged to capture login credentials in some browsers… | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | ROI Revolution Urchin | 26/9/2007 | 16/6/2026 | report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112. | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet. | |
| Modificada | Alta (7.5) | 3.7% | — | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname. | |
| Modificada | Media (4.3) | 1.2% | — | ROI Revolution Urchin | 5/9/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in urchin.cgi in Urchin 5.6.00r2 allow remote attackers to inject arbitrary web script or HTML via the (1) dtc, (2) vid, (3) n, (4) dt, (5) ed, and (6) bd parameters. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Envolution | 8/8/2007 | 16/6/2026 | SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a different vector than CVE-2005-4263. | |
| Modificada | Media (6.8) | 3.1% | — | Gnome Evolution | 19/6/2007 | 16/6/2026 | Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index. |