Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.94% | — | Nathan Haug Filefield Sources | 3/12/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the FileField Sources module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.6 for Drupal, when the field has "Reference existing" source enabled, allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file. | |
| Modificada | Media (6.8) | 0.93% | — | Larry Garfield Autosave | 14/8/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Autosave module 6.x before 6.x-2.10 and 7.x-2.x before 7.x-2.0 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests involving "submitting saved results to a node." | |
| Modificada | Media (6.8) | 3.7% | 💥 Exploit | EA Battlefield 2EA Battlefield 2142 | 2/7/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\" (dot dot backslash) sequences in URLs for the (1) sponsor or (2)… | |
| Modificada | Baja (2.1) | 0.99% | — | Quicksketch Filefield | 21/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter). | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | COM Perchafieldsattach | 25/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Baja (2.1) | 1.0% | — | Kevinhankens Tablefield | 20/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the CCK TableField module 6.x before 6.x-1.2 for Drupal allows remote authenticated users, with certain node creation or editing privileges, to inject arbitrary web script or HTML via table headers. | |
| Modificada | Alta (7.5) | 2.2% | — | Quicksketch Filefield | 26/10/2009 | 16/6/2026 | The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors. | |
| Modificada | Media (6.5) | 0.86% | 💥 Exploit | Formfields Adman | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbitrary SQL commands via the campaignId parameter. | |
| Modificada | Media (6.8) | 0.98% | 💥 Exploit | Myiosoft Easyclassifields | 15/9/2008 | 16/6/2026 | SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action. | |
| Modificada | Baja (3.5) | 0.84% | — | Drupal Asin Field ModuleDrupalDrupal E-commerce ModuleDrupal Fullname Field FOR CCK+6 | 22/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Token module before 4.7.x-1.5, and 5.x before 5.x-1.9, for Drupal; as used by the ASIN Field, e-Commerce, Fullname field for CCK, Invite, Node Relativity, Pathauto, PayPal Node, and Ubercart modules; allow remote authenticated users with a post comments… | |
| Modificada | Alta (7.5) | 1.7% | — | Drupal Audio ModuleDrupal Getid3Drupal Mediafield Module | 21/2/2007 | 16/6/2026 | Unspecified vulnerability in certain demonstration scripts in getID3 1.7.1, as used in the Mediafield and Audio modules for Drupal, allows remote attackers to read and delete arbitrary files, list arbitrary directories, and write to empty files or .mp3 files via unknown vectors. | |
| Modificada | Media (5) | 5.7% | — | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 21/7/2006 | 16/6/2026 | Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows remote attackers to include arbitrary files via a full Windows path and drive letter in the (1) language parameter in accounts/inc/include.php… | |
| Modificada | Media (4) | 2.1% | — | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 21/7/2006 | 16/6/2026 | Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer before 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Windows or UNC pathname in the… | |
| Modificada | Media (6.5) | 8.5% | 💥 Exploit | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 28/12/2005 | 16/6/2026 | IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users to include arbitrary PHP code via a URL… | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 28/12/2005 | 16/6/2026 | PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters… | |
| Modificada | Media (5) | 8.6% | 💥 Exploit | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 28/12/2005 | 16/6/2026 | mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and layout_settings variables when an unrecognized HTTP_USER_AGENT string is provided, which allows remote attackers to access arbitrary files… | |
| Modificada | Media (5) | 9.5% | 💥 Exploit | Deerfield Visnetic Mail ServerIcewarp WEB MailMerak Mail Server | 28/12/2005 | 16/6/2026 | dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulnerability. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Digital Illusions Battlefield 1942Digital Illusions Battlefield Vietnam | 10/1/2005 | 16/6/2026 | Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference. | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Electronic Arts Battlefield 1942 | 31/12/2003 | 16/6/2026 | Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password. | |
| Modificada | Media (5) | 2.8% | — | Deerfield Visnetic Website | 18/8/2003 | 16/6/2026 | VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Deerfield Visnetic Website | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page. | |
| Modificada | Media (5) | 4.9% | — | Deerfield D2gfxWorking Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents. | |
| Modificada | Media (5) | 1.2% | — | Deerfield Website PRO | 31/12/2002 | 16/6/2026 | WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name. | |
| Modificada | Media (5) | 1.6% | — | Deerfield Visnetic Website | 31/12/2002 | 16/6/2026 | Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request. | |
| Modificada | Media (5) | 2.6% | — | Deerfield FTP Serv-u | 14/11/2000 | 16/6/2026 | FTP Serv-U 2.5e allows remote attackers to cause a denial of service by sending a large number of null bytes. |