Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | B2evolution | 15/5/2007 | 16/6/2026 | Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the core_subdir parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | B2evolution | 30/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3)… | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Post Revolution | 24/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php. | |
| Modificada | Media (6.8) | 1.7% | 💥 Exploit | Tumusika Evolution | 18/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Revolutionproducts Flexbb | 28/3/2007 | 16/6/2026 | SQL injection vulnerability in includes/start.php in Flexbb 1.0.0 10005 Beta Release 1 allows remote attackers to execute arbitrary SQL commands via the flexbb_lang_id COOKIE parameter to index.php. | |
| Modificada | Media (6.8) | 3.4% | — | Evolution Shared Memo | 21/3/2007 | 16/6/2026 | Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo. | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Gnome Evolution | 6/3/2007 | 16/6/2026 | Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection. | |
| Modificada | Media (4.3) | 1.3% | — | B2evolution | 11/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Envolution | 10/12/2006 | 16/6/2026 | Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by… | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | B2evolution | 10/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | B2evolution | 1/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Phoenix Evolution CMS | 29/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Comscripts News Evolution | 11/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) install.php and (2) migrateNE2toNE3.php. | |
| Modificada | Media (5) | 1.8% | 💥 Exploit | Full Revolution Aspweblinks | 6/6/2006 | 16/6/2026 | links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Full Revolution Aspweblinks | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter. | |
| Modificada | Baja (2.6) | 2.1% | — | Gnome Evolution | 2/6/2006 | 16/6/2026 | Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used. | |
| Modificada | Media (5) | 2.0% | — | Gnome Evolution | 10/3/2006 | 16/6/2026 | GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Gnome Evolution | 2/2/2006 | 16/6/2026 | The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Envolution | 15/12/2005 | 16/6/2026 | SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter. | |
| Modificada | Media (4.3) | 1.0% | 💥 Exploit | Envolution | 15/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263). | |
| Modificada | Alta (7.5) | 4.4% | — | Gnome Evolution | 12/8/2005 | 16/6/2026 | Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers. | |
| Modificada | Alta (7.5) | 4.4% | — | Gnome Evolution | 12/8/2005 | 16/6/2026 | Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+5 | 2/5/2005 | 16/6/2026 | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has… | |
| Modificada | Media (5) | 1.7% | — | Ximian Evolution | 2/5/2005 | 16/6/2026 | Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames. | |
| Modificada | Media (5) | 1.7% | — | Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+5 | 2/5/2005 | 16/6/2026 | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that… |