Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Limesurvey | 6/6/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action. | |
| Modificada | Media (4.3) | 1.1% | — | Bluemoon BackpackBluemoon BmsurveyBluemoon Newbb FileupBluemoon News Fileup+3 | 30/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote… | |
| Modificada | Media (6.8) | 8.0% | 💥 Exploit | Toshiba Surveillix | 23/1/2008 | 16/6/2026 | Multiple buffer overflows in Toshiba Surveillance (Surveillix) RecordSend ActiveX control (MeIpCamX.DLL 1.0.0.4) allow remote attackers to execute arbitrary code via long arguments to the (1) SetPort and (2) SetIpAddress methods. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Limesurvey | 18/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter. | |
| Modificada | Alta (10) | 3.0% | — | Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP | 6/9/2007 | 16/6/2026 | The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote… | |
| Modificada | Alta (9) | 2.1% | — | Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP | 6/9/2007 | 16/6/2026 | The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passwords for the sypixx and root user accounts, which allows… | |
| Modificada | Media (6.8) | 62% | 💥 Exploit | Limesurvey | 10/7/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5)… | |
| Modificada | Alta (7.8) | 3.2% | — | HP Procurve Switch 9300m | 4/5/2007 | 16/6/2026 | Unspecified vulnerability in HP ProCurve 9300m Series switches with software 08.0.01c through 08.0.01j allows remote attackers to cause a denial of service via unknown vectors, a different switch series than CVE-2006-4015. | |
| Modificada | Media (6.8) | 3.2% | 💥 Exploit | Opensurveypilot | 22/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfgPathToProjectAdmin parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Fisasp.com Ultimate Survey PRO | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.asp in Ultimate Survey Pro allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) did parameter. | |
| Modificada | Media (5) | 4.4% | — | HP Procurve Switch 3500ylHP Procurve Switch 5400zlHP Procurve Switch 6200yl | 7/8/2006 | 16/6/2026 | Hewlett-Packard (HP) ProCurve 3500yl, 6200yl, and 5400zl switches with software before K.11.33 allow remote attackers to cause a denial of service (possibly memory leak or system crash) via unknown vectors. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Phpsurveyor | 27/4/2006 | 16/6/2026 | SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then… | |
| Modificada | Alta (7.5) | 2.1% | — | Philip Loftin Aspsurvey | 13/1/2006 | 16/6/2026 | SQL injection vulnerability in Login_Validate.asp in ASPSurvey 1.10 allows remote attackers to execute arbitrary SQL commands via the Password parameter to login.asp. | |
| Modificada | Media (4.6) | 0.59% | — | Autodesk 3DS MAXAutodesk Architectural DesktopAutodesk AutocadAutodesk Autocad Civil 3D+14 | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329. | |
| Modificada | Alta (7.5) | 1.4% | — | Phpsurveyor | 30/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHPSurveyor before 0.991 allow remote attackers to execute arbitrary SQL commands via the (1) sql parameter in browse.php and the (2) sid, (3) lid, (4) gid, and (5) token parameters in certain PHP scripts. | |
| Modificada | Alta (7.5) | 1.2% | — | PHP Labs Survey Wizard | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | PHP Surveyor | 27/7/2005 | 16/6/2026 | PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php. | |
| Modificada | Alta (7.5) | 2.9% | — | PHP Surveyor | 27/7/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Surveyor 0.98 allows remote attackers to execute arbitrary SQL commands via (1) the sid, start, and id parameters to browse.php, the sid parameter to (2) dataentry.php, (3) export.php, (4) admin.php, (5) conditions.php, (6) spss.php, (7) deletesurvey.php, (8)… | |
| Modificada | Media (5) | 1.2% | — | PHP Surveyor | 26/7/2005 | 16/6/2026 | PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to… | |
| Modificada | Media (5) | 1.0% | — | PHP Surveyor | 26/7/2005 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or the sid parameter to (4) dataentry.php or (5) export.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Geovision Digital Surveillance System | 14/5/2005 | 16/6/2026 | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0 uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via sniffing. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Geovision Digital Surveillance System | 14/5/2005 | 16/6/2026 | GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct request to the image. | |
| Modificada | Media (4.3) | 1.2% | — | Joel Palmius MOD Survey | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mod_survey 3.0.x before 3.0.16-pre2 and 3.2.x before 3.2.0-pre4 allows remote attackers to inject arbitrary web script or HTML via the certain survey fields or error messages for malformed query strings. | |
| Modificada | Media (5) | 1.4% | — | MOD Survey | 31/12/2003 | 16/6/2026 | mod_survey 3.0.0 through 3.0.15-pre6 does not check whether a survey exists before creating a subdirectory for it, which allows remote attackers to cause a denial of service (disk consumption and possible crash). | |
| Modificada | Alta (7.8) | 20% | 💥 Exploit | HP Procurve Switch 4000m | 11/4/2003 | 16/6/2026 | HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow. |