Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.6)1.4%—Stefan Ritt Elog WEB Logbook7/11/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct function, and (2) the Type or Category values in a New entry,…
ModificadaAlta (7.5)3.1%—Stefan Ritt Elog WEB Logbook7/11/200616/6/2026
Multiple format string vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) an entry with an attachment whose name contains format string specifiers (el_submit function), and possibly other vectors in the (2)…
ModificadaMedia (5.1)1.4%—Stefan Ritt Elog WEB Logbook28/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in Elog 2.6.1 allows remote attackers to inject arbitrary web script or HTML by editing log entries in HTML mode.
ModificadaMedia (5.1)1.1%—Dian Gemilang Dgbook24/5/200616/6/2026
SQL injection vulnerability in index.php in DGBook 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) homepage, (4) address, (5) comment, and (6) ip parameters. NOTE: the provenance of this information is unknown; the details are obtained…
ModificadaBaja (2.6)1.4%—Dian Gemilang Dgbook24/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in DGBook 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) email, and (4) address parameters.
ModificadaAlta (7.5)2.9%—Stefan Ritt Elog WEB Logbook13/2/200616/6/2026
Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file.
ModificadaMedia (5)1.8%—Stefan Ritt Elog WEB Logbook13/2/200616/6/2026
elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with the fail parameter set to 1, which redirects to the same request.
ModificadaMedia (5)1.6%—Stefan Ritt Elog WEB Logbook13/2/200616/6/2026
The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.
ModificadaAlta (7.5)2.8%—Stefan Ritt Elog WEB Logbook13/2/200616/6/2026
Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of service (application crash) and possibly execute code via long "revision attributes".
ModificadaMedia (5)2.0%—Stefan Ritt Elog WEB Logbook21/1/200616/6/2026
Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.
ModificadaMedia (5)1.9%—Stefan Ritt Elog WEB Logbook21/1/200616/6/2026
Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5.1)1.7%—Martin Bauer Gbook31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header field.
ModificadaAlta (7.5)1.7%—Stefan Ritt Elog WEB Logbook2/5/200516/6/2026
ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.
ModificadaAlta (7.5)10%💥 ExploitStefan Ritt Elog WEB Logbook2/5/200516/6/2026
Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.
ModificadaMedia (4.3)1.3%—Martin Bauer Gbook31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke.
ModificadaMedia (4.3)1.3%—Martin Bauer Gbook31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via cookies that are stored in the $_COOKIE PHP variable, which is not cleansed by PHP-Nuke.
ModificadaAlta (10)10%💥 ExploitMartin Bauer Gbook31/3/200316/6/2026
index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.
ModificadaMedia (4.3)1.5%💥 ExploitScript Shed Ssgbook31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject arbitrary web script or HTML via a javascript: URL in (1) image, (2) img, (3) image=right, (4) img=right, (5) image=left, and (6) img=left tags.
ModificadaAlta (7.5)3.4%—Bill Kendrick Gbook.cgi9/1/200116/6/2026
Bill Kendrick web site guestbook (GBook) allows remote attackers to execute arbitrary commands via shell metacharacters in the _MAILTO form variable.
Orbitaley — Vulnerabilidades