Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

439 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—B2evolution15/5/200716/6/2026
Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the core_subdir parameter.
ModificadaAlta (7.5)2.5%—B2evolution30/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3)…
ModificadaAlta (7.5)4.1%💥 ExploitPost Revolution24/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php.
ModificadaMedia (6.8)1.7%💥 ExploitTumusika Evolution18/4/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaAlta (7.5)1.3%—Revolutionproducts Flexbb28/3/200716/6/2026
SQL injection vulnerability in includes/start.php in Flexbb 1.0.0 10005 Beta Release 1 allows remote attackers to execute arbitrary SQL commands via the flexbb_lang_id COOKIE parameter to index.php.
ModificadaMedia (6.8)3.4%—Evolution Shared Memo21/3/200716/6/2026
Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo.
ModificadaMedia (5)5.2%💥 ExploitGnome Evolution6/3/200716/6/2026
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection.
ModificadaMedia (4.3)1.3%—B2evolution11/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter.
ModificadaAlta (7.5)6.7%💥 ExploitEnvolution10/12/200616/6/2026
Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by…
ModificadaAlta (7.5)3.4%💥 ExploitB2evolution10/12/200616/6/2026
PHP remote file inclusion vulnerability in inc/CONTROL/import/import-mt.php in b2evolution 1.8.5 through 1.9 beta allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter.
ModificadaMedia (6.8)1.9%💥 ExploitB2evolution1/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in b2evolution 1.8.2 through 1.9 beta allow remote attackers to inject arbitrary web script or HTML via the (1) app_name parameter in (a) _404_not_found.page.php, (b) _410_stats_gone.page.php, and (c) _referer_spam.page.php in inc/VIEW/errors/; the (2) baseurl…
ModificadaMedia (6.8)1.9%💥 ExploitPhoenix Evolution CMS29/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the…
ModificadaAlta (7.5)2.5%💥 ExploitComscripts News Evolution11/9/200616/6/2026
PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) install.php and (2) migrateNE2toNE3.php.
ModificadaMedia (5)1.8%💥 ExploitFull Revolution Aspweblinks6/6/200616/6/2026
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.
ModificadaAlta (7.5)1.3%💥 ExploitFull Revolution Aspweblinks6/6/200616/6/2026
SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter.
ModificadaBaja (2.6)2.1%—Gnome Evolution2/6/200616/6/2026
Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used.
ModificadaMedia (5)2.0%—Gnome Evolution10/3/200616/6/2026
GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml.
ModificadaMedia (5)11%💥 ExploitGnome Evolution2/2/200616/6/2026
The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to…
ModificadaAlta (7.5)1.1%💥 ExploitEnvolution15/12/200516/6/2026
SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.
ModificadaMedia (4.3)1.0%💥 ExploitEnvolution15/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE-2005-4263).
ModificadaAlta (7.5)4.4%—Gnome Evolution12/8/200516/6/2026
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.
ModificadaAlta (7.5)4.4%—Gnome Evolution12/8/200516/6/2026
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.
ModificadaMedia (5)3.1%💥 ExploitFunlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+52/5/200516/6/2026
Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has…
ModificadaMedia (5)1.7%—Ximian Evolution2/5/200516/6/2026
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.
ModificadaMedia (5)1.7%—Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+52/5/200516/6/2026
Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that…