Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | B2evolution | 10/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | B2evolution | 1/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Phoenix Evolution CMS | 29/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Comscripts News Evolution | 11/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) install.php and (2) migrateNE2toNE3.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Full Revolution Aspweblinks | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter. | |
| Modificada | Media (5) | 1.8% | 💥 Exploit | Full Revolution Aspweblinks | 6/6/2006 | 16/6/2026 | links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field. | |
| Modificada | Baja (2.6) | 2.1% | — | Gnome Evolution | 2/6/2006 | 16/6/2026 | Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used. | |
| Modificada | Media (5) | 2.0% | — | Gnome Evolution | 10/3/2006 | 16/6/2026 | GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Gnome Evolution | 2/2/2006 | 16/6/2026 | The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to… | |
| Modificada | Alta (7.5) | 4.4% | — | Gnome Evolution | 12/8/2005 | 16/6/2026 | Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers. | |
| Modificada | Alta (7.5) | 4.4% | — | Gnome Evolution | 12/8/2005 | 16/6/2026 | Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab. | |
| Modificada | Media (5) | 1.7% | — | Ximian Evolution | 2/5/2005 | 16/6/2026 | Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames. | |
| Modificada | Media (5) | 1.7% | — | Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+5 | 2/5/2005 | 16/6/2026 | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that… | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+5 | 2/5/2005 | 16/6/2026 | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has… | |
| Modificada | Crítica (9.8) | 3.2% | — | Gnome EvolutionDebian Linux | 24/1/2005 | 16/6/2026 | Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Fullrevolution Aspwebalbum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a… | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Full Revolution Aspwebcalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Evolutionx | 23/11/2004 | 16/6/2026 | Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1) a long cd command to the FTP server, or (2) a long dir command to the telnet server. | |
| Modificada | Alta (7.5) | 2.2% | — | Ximian Evolution | 16/6/2003 | 16/6/2026 | The IMAP Client for Evolution 1.2.4 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors. | |
| Modificada | Media (5) | 3.4% | — | Microsoft Outlook ExpressMozillaMuttQualcomm Eudora+4 | 16/6/2003 | 16/6/2026 | The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors. | |
| Modificada | Media (5) | 0.92% | — | Ximian Evolution | 22/4/2003 | 16/6/2026 | The camel component for Ximian Evolution 1.0.x and earlier does not verify certificates when it establishes a new SSL connection after previously verifying a certificate, which could allow remote attackers to monitor or modify sessions via a man-in-the-middle attack. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Ximian Evolution | 24/3/2003 | 16/6/2026 | The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers to inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image. | |
| Modificada | Media (5) | 17% | 💥 Exploit | Ximian Evolution | 24/3/2003 | 16/6/2026 | The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Ximian Evolution | 24/3/2003 | 16/6/2026 | Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times. | |
| Modificada | Media (5) | 1.6% | — | Ximian Evolution | 31/12/2002 | 16/6/2026 | Evolution 1.0.3 and 1.0.4 allows remote attackers to cause a denial of service (memory consumption and crash) via an email with a malformed MIME header. |