Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Steveyolam Tinyguestbook | 23/9/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | Steveyolam Tinyguestbook | 23/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Media (6) | 1.1% | — | Karen Stevenson Date | 20/9/2012 | 16/6/2026 | SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Steve Lockwood Ticketyboo News Ticker | 17/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 13% | — | Steve J Baker Plib | 31/12/2011 | 16/6/2026 | Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained… | |
| Modificada | Media (5) | 2.6% | — | Karen Stevenson CCKYves Chedemois CCK | 21/6/2010 | 16/6/2026 | The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced nodes, which allows remote attackers to read controlled nodes. | |
| Modificada | Baja (2.1) | 1.2% | — | Steven Jones Context | 19/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description. | |
| Modificada | Alta (10) | 1.3% | — | Steve Lockwood Node2node | 24/9/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors. | |
| Modificada | Baja (3.5) | 1.00% | — | Karen Stevenson Calendar | 10/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web script or HTML via the title of a content type. | |
| Modificada | Baja (2.1) | 1.2% | — | DrupalKaren Stevenson Date | 10/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script or HTML via a "Content type label" field. | |
| Modificada | Baja (3.5) | 0.87% | — | Karen Stevenson CCKYves Chedemois CCK | 13/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Drupal Content Construction Kit (CCK) 5.x through 5.x-1.8 allow remote authenticated users with "administer content" permissions to inject arbitrary web script or HTML via the (1) "field label," (2) "help text," or (3) "allowed values" settings. | |
| Modificada | Alta (7.5) | 1.1% | — | Steve Grundell Frontend MP3 Player | 17/6/2009 | 16/6/2026 | SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.9) | 0.37% | — | Steve Robbins MGT | 6/11/2008 | 16/6/2026 | mailgo in mgt 2.31 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mailgo##### temporary file. | |
| Modificada | Alta (7.5) | 2.7% | — | Steve Dawson Pokermax Poker League Tournament Script | 18/10/2008 | 16/6/2026 | configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie. | |
| Modificada | Alta (7.5) | 3.1% | — | Steve Poulsen Guildftpd | 3/10/2006 | 16/6/2026 | Buffer overflow in GuildFTPd 0.999.13 allows remote attackers to have an unknown impact, possibly code execution related to input containing "globbing chars." | |
| Modificada | Media (4.6) | 0.35% | — | Steven Schaefer Sophster | 31/12/2004 | 16/6/2026 | The Change Permissions function in the Sophster suite before 0.9.6 28 May 2004 (aka 0.9.6-r5), possibly including Sophster, FreeSophster, and FreeSophsterPAM, removes the (1) setuid, (2) setgid, and (3) sticky bits when changing a file, which might allow attackers to gain privileges or conduct other unauthorized… | |
| Modificada | Media (5) | 1.7% | — | Steve Poulsen Guildftpd | 31/12/2003 | 16/6/2026 | GuildFTPd 0.999 allows remote attackers to cause a denial of service (crash) via a GET request for MS-DOS device names such as lpt1. | |
| Modificada | Media (5) | 0.83% | — | Steve Sachs Charities.cron | 31/12/2002 | 16/6/2026 | Charities.cron 1.0.2 through 1.6.0 allows local users to write to arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 7.0% | — | Steve Korbett Pvote | 18/6/2002 | 16/6/2026 | PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password. | |
| Modificada | Media (5) | 6.6% | — | Steve Korbett Pvote | 18/6/2002 | 16/6/2026 | PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php. | |
| Modificada | Media (5) | 7.5% | — | Steve Kneizys Agora.cgi | 16/5/2002 | 16/6/2026 | Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message. | |
| Modificada | Alta (7.5) | 8.7% | — | Steve Kneizys Agora.cgi | 17/12/2001 | 16/6/2026 | Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote attackers to execute Javascript on other clients via the cart_id parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Steve Poulsen Guildftpd | 18/10/2001 | 16/6/2026 | Buffer overflow in GuildFTPd Server 0.97 allows remote attacker to execute arbitrary code via a long SITE command. | |
| Modificada | Media (5) | 1.7% | — | Steve Poulsen Guildftpd | 18/10/2001 | 16/6/2026 | Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET. | |
| Modificada | Media (5) | 1.3% | — | Steve Poulsen Guildftpd | 18/10/2001 | 16/6/2026 | Memory leak in GuildFTPd Server 0.97 allows remote attackers to cause a denial of service via a request containing a null character. |