Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | PS Project Management Team Libunity-webapps | 30/11/2012 | 16/6/2026 | Use-after-free vulnerability in libunity-webapps before 2.4.1 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted web site, related to "certain hash tables." | |
| Modificada | Alta (7.5) | 3.5% | — | PS Project Management Team Unity-firefox-extension | 24/11/2012 | 16/6/2026 | Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request. | |
| Modificada | Alta (10) | 26% | 💥 Exploit | Invisioncommunity Invision Power BoardInvisionpower Invision Power Board | 31/10/2012 | 16/6/2026 | Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3.x has unknown impact and remote attack vectors. | |
| Modificada | Alta (7.5) | 1.9% | — | Scripte24shop Social Network Community | 25/10/2012 | 16/6/2026 | SQL injection vulnerability in user.php in Social Network Community 2 allows remote attackers to execute arbitrary SQL commands via the userId parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | 2daybiz Video Community Portal Script | 25/10/2012 | 16/6/2026 | SQL injection vulnerability in index.php in Video Community Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4) | 0.97% | — | Cisco Unity Connection | 16/9/2012 | 16/6/2026 | Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of service (resource consumption and administration outage) via extended use of the product, aka Bug ID CSCtd79132. | |
| Modificada | Alta (7.8) | 1.3% | — | Cisco Unity Connection | 16/9/2012 | 16/6/2026 | Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka Bug ID CSCtz76269. | |
| Modificada | Baja (2.1) | 0.39% | — | Redhat Jboss Community Application ServerRedhat Jboss Enterprise Application Platform | 13/8/2012 | 16/6/2026 | twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Tbelmans MM Forms Community | 16/6/2012 | 16/6/2026 | Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/temp. | |
| Modificada | Media (4) | 1.9% | — | MysqlMysql Community ServerMysql ServerOracle Mysql+1 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. | |
| Modificada | Alta (7.8) | 2.6% | — | Cisco Unity Connection | 1/3/2012 | 16/6/2026 | Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899. | |
| Modificada | Alta (9) | 2.3% | — | Cisco Unity Connection | 1/3/2012 | 16/6/2026 | Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Administrator role, aka Bug ID CSCtd45141. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Efrontlearning Efront Community ++ | 12/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Joomlaextensions COM Hmcommunity | 14/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) language[], (2) university[], (3) persent[], (4) company_name[], (5) designation[], (6) music[], (7) books[], (8)… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Joomlaextensions COM Hmcommunity | 14/12/2011 | 16/6/2026 | SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a fnd_home action to index.php. | |
| Modificada | Alta (7.2) | 1.3% | — | Schneider-electric Monitor PROSchneider-electric OPC Factory ServerSchneider-electric PL7 PROSchneider-electric Telemecanique Driver Pack+2 | 4/11/2011 | 16/6/2026 | Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers,… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | 2daybiz Network Community Script | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter. | |
| Modificada | Media (6.8) | 1.5% | — | Jasperforge Jasperreports Server Community Project | 20/9/2011 | 16/6/2026 | JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach. | |
| Modificada | Media (4.3) | 1.0% | — | Invisioncommunity Invision Power Board | 16/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/sources/classes/bbcode/custom/defaults.php in Invision Power Board (IP.Board) 3.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.2% | 💥 Exploit | Sijio Community Software | 12/7/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sijio Community Software allow remote authenticated users to inject arbitrary web script or HTML via the title parameter when (1) editing a new blog, (2) adding an album, or (3) editing an album. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Baja (3.5) | 1.3% | 💥 Exploit | Sijio Community Software | 12/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sijio Community Software allows remote authenticated users to inject arbitrary web script or HTML via the title parameter when adding a new blog, related to edit_blog/index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Sijio Community Software | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in gallery/index.php in Sijio Community Software allows remote attackers to execute arbitrary SQL commands via the parent parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | 2daybiz Video Community Portal Script | 28/6/2010 | 16/6/2026 | SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | 2daybiz Video Community Portal Script | 25/6/2010 | 16/6/2026 | SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | 2daybiz Video Community Portal Script | 25/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter. |