Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 1.9% | 💥 Exploit | Php-update | 31/12/2006 | 16/6/2026 | Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated users to upload arbitrary PHP scripts to the gfx/ and files/ directories via the userfile parameter. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Php-update | 20/12/2006 | 16/6/2026 | Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission… | |
| Modificada | Alta (7.5) | 1.8% | — | Lumension Patchlink Update ServerNovell Zenworks | 7/7/2006 | 16/6/2026 | SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid parameter. | |
| Modificada | Media (5) | 2.7% | — | Lumension Patchlink Update ServerNovell Zenworks | 7/7/2006 | 16/6/2026 | Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to… | |
| Modificada | Alta (7.5) | 2.3% | — | Lumension Patchlink Update ServerNovell Zenworks | 7/7/2006 | 16/6/2026 | FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List,… | |
| Modificada | Media (6.8) | 0.39% | — | Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+2 | 19/4/2006 | 16/6/2026 | Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program. | |
| Modificada | Media (4.3) | 4.2% | 💥 Exploit | Fatwire Updateengine | 29/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters. | |
| Modificada | Alta (7.5) | 2.7% | — | Ipupdate | 23/11/2005 | 16/6/2026 | Multiple buffer overflows in IPUpdate 1.1 might allow attackers to execute arbitrary code via (1) memmcat in the memm module or (2) certain TSIG format records. | |
| Modificada | Alta (7.5) | 3.1% | — | Xzabite Dyndnsupdate | 2/5/2005 | 16/6/2026 | Multiple buffer overflows in Xzabite DYNDNSUpdate 0.6.15 and earlier, including the ipcheck function in dyndnsupdate.c, allow remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (10) | 3.8% | — | Angus Mackay Ez-ipupdateDebian LinuxGentoo Linux | 9/2/2005 | 16/6/2026 | Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code. | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System WorksSymantec Windows Liveupdate | 3/2/2004 | 16/6/2026 | The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges. | |
| Modificada | Baja (2.1) | 0.29% | — | Angus Mackay Ez-ipupdate | 31/12/2003 | 16/6/2026 | ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file. | |
| Modificada | Media (5) | 2.0% | — | Pyramid Benhur Software Update | 31/12/2002 | 16/6/2026 | The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20. | |
| Modificada | Media (5) | 2.8% | — | Symantec Liveupdate | 25/6/2002 | 16/6/2026 | Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server. | |
| Modificada | Crítica (9.8) | 2.5% | — | Symantec Liveupdate | 5/10/2001 | 16/6/2026 | Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site. | |
| Modificada | Media (5) | 2.6% | — | Symantec Liveupdate | 5/10/2001 | 16/6/2026 | Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. | |
| Modificada | Media (4.6) | 0.38% | — | Symantec Liveupdate | 14/8/2001 | 16/6/2026 | Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | CGI Script Center News Update | 19/12/2000 | 23/9/2026 | CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password change operation, which allows remote attackers to modify the password without knowing the original password. | |
| Modificada | Media (6.2) | 0.31% | — | Helix Code Gnome Updater | 20/10/2000 | 16/6/2026 | Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages. |