Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
447 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Actualscripts Actualanalyzer GoldActualscripts Actualanalyzer LiteActualscripts Actualanalyzer PROActualscripts Actualanalyzer Server | 3/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view.php in ActualScripts ActualAnalyzer Server 8.37 and earlier, ActualAnalyzer Gold 7.74 and earlier, ActualAnalyzer Pro 6.95 and earlier, and ActualAnalyzer Lite 2.78 and earlier allows remote attackers to inject arbitrary web script or HTML via the language parameter. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Actualscripts Actualanalyzer Lite | 5/5/2008 | 16/6/2026 | Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the style parameter. | |
| Modificada | Baja (3.5) | 0.83% | — | Manageengine Firewall Analyzer | 14/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mindex.do in ManageEngine Firewall Analyzer 4.0.3 allows remote attackers to inject arbitrary web script or HTML via the displayName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.84% | — | Manageengine Eventlog Analyzer | 28/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searchAction.do in ManageEngine EventLog Analyzer 5 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Fixed in… | |
| Modificada | Alta (7.5) | 1.4% | — | Adventnet Eventlog Analyzer | 21/11/2007 | 16/6/2026 | AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" account without a password, which allows remote attackers to gain privileges and modify logs. Fixed in EventLog Analyzer Build 6000. | |
| Modificada | Media (6.8) | 3.7% | 💥 Exploit | Eiqnetworks Enterprise Security Analyzer | 29/10/2007 | 16/6/2026 | Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arbitrary code via certain data on TCP port 10616 that results in a long argument to the SEARCHREPORT command, a different vector than CVE-2007-2059. | |
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Adventnet Manageengine Netflow Analyzer | 6/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine NetFlow Analyzer 5 allow remote attackers to inject arbitrary web script or HTML via the (1) alpha parameter in (a) netflow/jspui/applicationList.jsp, the (2) task parameter in (b) netflow/jspui/appConfig.jsp, the (3) view parameter in (c)… | |
| Modificada | Baja (2.6) | 5.8% | 💥 Exploit | Adventnet Manageengine Netflow Analyzer | 6/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AdventNet ManageEngine OpManager 6 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in (a) ping.do and (b) traceRoute.do in map/; the (2) reportName, (3) displayName, and (4) selectedNode parameters to (c)… | |
| Modificada | Alta (10) | 7.3% | 💥 Exploit | Eiqnetworks Enterprise Security Analyzer | 18/4/2007 | 16/6/2026 | Multiple buffer overflows in the ESA protocol implementation in eIQnetworks Enterprise Security Analyzer (ESA) 2.5 allow remote attackers to execute arbitrary code via a long parameter to the (1) DELETESEARCHFOLDER, (2) DELTASK, (3) HMGR_CHECKHOSTSCSV, (4) TASKUPDATEDUSER, (5) VERIFYUSERKEY, or (6) VERIFYPWD command. | |
| Modificada | Media (4) | 1.2% | — | Manageengine Firewall Analyzer | 24/3/2007 | 16/6/2026 | Unspecified vulnerability in ManageEngine Firewall Analyzer allows remote authenticated users to "access any common file" via a direct URL request. | |
| Modificada | Baja (2.1) | 0.37% | — | Norman Sandbox Analyzer | 2/3/2007 | 16/6/2026 | Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Eiqnetworks Enterprise Security Analyzer | 13/1/2007 | 16/6/2026 | The DataCollector service in EIQ Networks Network Security Analyzer allows remote attackers to cause a denial of service (service crash) via a (1) &CONNECTSERVER& (2) &ADDENTRY& (3) &FIN& (4) &START& (5) &LOGPATH& (6) &FWADELTA& (7) &FWALOG& (8) &SETSYNCHRONOUS& (9) &SETPRGFILE&, or (10) &SETREPLYPORT& string to TCP… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Phpprintanalyzer | 16/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ficStyle parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Thomas Pequet Phpprintanalyzer | 10/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has been disputed by third party researchers, stating that the… | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Eiqnetworks Enterprise Security Analyzer | 27/7/2006 | 16/6/2026 | Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, and possibly other products, allow remote… | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Actualscripts Actualanalyzer | 21/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Adventnet Manageengine Netflow Analyzer | 6/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | MS Analysis Website Traffic Analyzer | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in MS Analysis module 2.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL via the referer field in an HTTP request. | |
| Modificada | Media (4.3) | 1.3% | — | Nihuo Software WEB LOG Analyzer | 20/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Nihuo Web Log Analyzer 1.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header. | |
| Modificada | Media (5) | 3.2% | — | Microsoft Baseline Security Analyzer | 10/2/2004 | 16/6/2026 | Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security. | |
| Modificada | Media (5) | 16% | — | Microsoft Baseline Security Analyzer | 31/12/2002 | 16/6/2026 | Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious active content such as ActiveX controls or Java. | |
| Modificada | Baja (2.1) | 0.40% | — | Webtrends Enterprise SuiteWebtrends FOR FirewallsWebtrends LOG AnalyzerWebtrends Professional Suite+1 | 29/6/1999 | 16/6/2026 | WebTrends software stores account names and passwords in a file which does not have restricted access permissions. |