Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

55 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Steveyolam Tinyguestbook23/9/201216/6/2026
Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.2%—Steveyolam Tinyguestbook23/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaMedia (6)1.1%—Karen Stevenson Date20/9/201216/6/2026
SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.3%—Steve Lockwood Ticketyboo News Ticker17/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)13%—Steve J Baker Plib31/12/201116/6/2026
Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained…
ModificadaMedia (5)2.6%—Karen Stevenson CCKYves Chedemois CCK21/6/201016/6/2026
The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced nodes, which allows remote attackers to read controlled nodes.
ModificadaBaja (2.1)1.2%—Steven Jones Context19/5/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.
ModificadaAlta (10)1.3%—Steve Lockwood Node2node24/9/200916/6/2026
Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors.
ModificadaBaja (3.5)1.00%—Karen Stevenson Calendar10/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web script or HTML via the title of a content type.
ModificadaBaja (2.1)1.2%—DrupalKaren Stevenson Date10/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script or HTML via a "Content type label" field.
ModificadaBaja (3.5)0.87%—Karen Stevenson CCKYves Chedemois CCK13/8/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via the (1) "field label," (2) "help text," or (3) "allowed values" settings.
ModificadaAlta (7.5)1.1%—Steve Grundell Frontend MP3 Player17/6/200916/6/2026
SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.9)0.37%—Steve Robbins MGT6/11/200816/6/2026
mailgo in mgt 2.31 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mailgo##### temporary file.
ModificadaAlta (7.5)2.7%—Steve Dawson Pokermax Poker League Tournament Script18/10/200816/6/2026
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie.
ModificadaAlta (7.5)3.1%—Steve Poulsen Guildftpd3/10/200616/6/2026
Buffer overflow in GuildFTPd 0.999.13 allows remote attackers to have an unknown impact, possibly code execution related to input containing "globbing chars."
ModificadaMedia (4.6)0.35%—Steven Schaefer Sophster31/12/200416/6/2026
The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized…
ModificadaMedia (5)1.7%—Steve Poulsen Guildftpd31/12/200316/6/2026
GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1.
ModificadaMedia (5)0.83%—Steve Sachs Charities.cron31/12/200216/6/2026
Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files.
ModificadaAlta (7.5)7.0%—Steve Korbett Pvote18/6/200216/6/2026
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password.
ModificadaMedia (5)6.6%—Steve Korbett Pvote18/6/200216/6/2026
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php.
ModificadaMedia (5)7.5%—Steve Kneizys Agora.cgi16/5/200216/6/2026
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.
ModificadaAlta (7.5)8.7%—Steve Kneizys Agora.cgi17/12/200116/6/2026
Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter.
ModificadaAlta (7.5)3.2%—Steve Poulsen Guildftpd18/10/200116/6/2026
Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command.
ModificadaMedia (5)1.7%—Steve Poulsen Guildftpd18/10/200116/6/2026
Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET.
ModificadaMedia (5)1.3%—Steve Poulsen Guildftpd18/10/200116/6/2026
Memory leak in GuildFTPd Server 0.97 allows remote attackers to cause a denial of service via a request containing a null character.