Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | NET ART Media Iboutique.mall | 3/6/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in iBoutique.MALL and possibly iBoutique allows remote attackers to read arbitrary files via ".." sequences in the function parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Preprojects.com PRE Shopping Mall | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Pre Shopping Mall 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter in search.php (the "search box"), (2) the prodid parameter in detail.php, and the (3) cid parameter in products.php. | |
| Modificada | Media (5) | 64% | 💥 Exploit | Ipswitch Whatsup Small Business | 31/12/2005 | 16/6/2026 | Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022). | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ihtml Merchant MallAI | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in browse.ihtml in iHTML Merchant Mall allows remote attackers to execute arbitrary SQL commands via the (1) id, (2) store, and (3) step parameters. | |
| Modificada | Alta (7.5) | 1.3% | — | Mall23 | 22/9/2005 | 16/6/2026 | SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Mall23 | 22/9/2005 | 16/6/2026 | SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter. | |
| Modificada | Media (5) | 6.2% | — | Sophos Anti-virusSophos MailmonitorSophos Mailmonitor FOR Notes DominoSophos Puremessage Anti-virus+1 | 19/7/2005 | 16/6/2026 | Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value. | |
| Modificada | Alta (10) | 4.2% | — | Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+2 | 13/7/2005 | 16/6/2026 | The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 9/2/2005 | 16/6/2026 | Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Broadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus GatewayBroadcom Etrust EZ Antivirus+18 | 10/1/2005 | 16/6/2026 | Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | I-mall Commerce I-mall.cgi | 31/12/2004 | 16/6/2026 | i-mall.cgi in I-Mall Commerce allows remote attackers to execute arbitrary commands via shell metacharacters via the p parameter. | |
| Modificada | Baja (2.1) | 1.0% | 💥 Exploit | Smallftpd | 23/11/2004 | 16/6/2026 | Buffer overflow in smallftpd 0.99 allows local users to cause a denial of service (crash) via an FTP request with a large number of "/" (slash) characters. | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | Sophos Small Business Suite | 3/11/2004 | 16/6/2026 | Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Happycgi Happymall | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the file parameter. | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | Happycgi.com Happymall | 16/6/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in normal_html.cgi in Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to insert arbitrary web script via the file parameter. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Happycgi Happymall | 27/5/2003 | 16/6/2026 | Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts. | |
| Modificada | Media (5) | 17% | — | Novell Small Business SuiteNovell Netware | 11/4/2003 | 16/6/2026 | Directory traversal vulnerability in Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to read arbitrary files via a URL containing a "..%5c" sequence (modified dot-dot), which is mapped to the directory separator. | |
| Modificada | Media (5) | 2.7% | — | Novell Small Business SuiteNovell Netware | 11/4/2003 | 16/6/2026 | Buffer overflow in the interpreter for Novell NetBasic Scripting Server (NSN) for Netware 5.1 and 6, and Novell Small Business Suite 5.1 and 6, allows remote attackers to cause a denial of service (ABEND) via a long module name. | |
| Modificada | Media (5) | 1.6% | — | MAX Feoktistov Small Http ServerVwebserver | 29/6/2001 | 16/6/2026 | SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests. | |
| Modificada | Media (5) | 1.6% | — | MAX Feoktistov Small Http Server | 27/6/2001 | 16/6/2026 | Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux. |