Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
393 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.5% | — | AC Zoom Blockhosts | 18/5/2007 | 16/6/2026 | blockhosts.py in BlockHosts before 2.0.3 does not properly parse daemon log files, which allows remote attackers to add arbitrary deny entries to the /etc/hosts.allow file and cause a denial of service by adding arbitrary IP addresses to a daemon log file, as demonstrated by logging in through ssh using a login name… | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Mamboxchange COM Zoom | 12/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/. | |
| Modificada | Media (5.1) | 2.4% | 💥 Exploit | Zoomstats | 28/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Vbzoom | 8/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441. | |
| Modificada | Alta (7.5) | 1.7% | — | Vbzoom | 21/7/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in VBZooM 1.11 and earlier allow remote attackers to execute arbitrary SQL commands via the UserID parameter to (1) ignore-pm.php, (2) sendmail.php, (3) reply.php or (4) sub-join.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Vbzoom | 27/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in VBZooM 1.00 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) MemberID parameter to rank.php, and the (2) QuranID parameter to lng.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Vbzoom | 27/6/2006 | 16/6/2026 | SQL injection vulnerability in message.php in VBZooM 1.11 and earlier allows remote attackers to execute arbitrary SQL commands via the UserID parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Vbzoom | 22/6/2006 | 16/6/2026 | SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Vbzoom | 16/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in VBZooM 1.02 allow remote attackers to execute arbitrary SQL commands via the (1) QuranID, (2) ShowByQuranID, or (3) Action parameters to meaning.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Vbzoom | 16/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in VBZooM 1.11 allow remote attackers to execute arbitrary SQL commands via the (1) sobjectID or (2) MAINID parameters to (a) show.php or (3) MainID parameter to (b) subject.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Vbzoom | 16/6/2006 | 16/6/2026 | SQL injection vulnerability in language.php in VBZooM 1.01 allows remote attackers to execute arbitrary SQL commands via the Action parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Vbzoom | 10/3/2006 | 16/6/2026 | SQL injection vulnerability in show.php in vbzoom 1.11 allow remote attackers to execute arbitrary SQL commands via the MainID parameter. NOTE: the SubjectID vector is already covered by CVE-2005-4729. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Vbzoom | 10/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script or HTML via the UserID parameter to (1) comment.php or (2) contact.php. NOTE: the profile.php/UserName vector is already covered by CVE-2005-2441. | |
| Modificada | Alta (7.5) | 1.5% | — | Vbzoom | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in show.php in VBZooM Forum allows remote attackers to execute arbitrary SQL commands via the SubjectID parameter. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Vbzoom | 3/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Zoom Media GalleryAI | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Alta (10) | 3.6% | — | Zoom Model 5560 X3 Ethernet Adsl Modem | 6/8/2004 | 16/6/2026 | Zoom X3 ADSL modem has a terminal running on port 254 that can be accessed using the default HTML management password, even if the password has been changed for the HTTP interface, which could allow remote attackers to gain unauthorized access. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Wrensoft Zoom Search Engine | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject arbitrary web script or HTML via the zoom_query parameter. |