Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Blackboard Learning AND Community Post Systems | 5/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web script or HTML via the (1) subject_t and (2) body_text parameters. NOTE: vector 2 requires bypassing… | |
| Modificada | Baja (3.5) | 1.6% | — | Mysql Community Server | 15/7/2007 | 16/6/2026 | MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table. | |
| Modificada | Media (5) | 14% | — | Mysql Community Server | 15/7/2007 | 16/6/2026 | MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol. | |
| Modificada | Media (4) | 1.8% | — | Mysql Community Server | 15/7/2007 | 16/6/2026 | MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Cuttlefish Leicestershire Communityportals | 7/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in… | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Cliserv WEB Community | 2/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Communityserver.org Community Server | 14/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 1.5% | — | Telligent Systems Community Server Forums | 29/1/2007 | 16/6/2026 | Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content… | |
| Modificada | Alta (7.8) | 3.0% | 💥 Exploit | Arsdigita Community Education SolutionArsdigita Community System | 19/1/2007 | 16/6/2026 | Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Invision Power Services Invision Community Blog | 7/12/2006 | 16/6/2026 | SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Dynamic Dataworx Nucommunity | 14/11/2006 | 16/6/2026 | SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Leicestershire Communityportals | 6/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in cpadmin/cpa_index.php in Leicestershire communityPortals 1.0_2005-10-18_12-31-18 allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. | |
| Modificada | Media (6.8) | 1.9% | — | Cuttlefish Multimedia Ltd. Leicestershire Communityportals | 13/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/import-archive.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter. | |
| Modificada | Media (5.1) | 1.4% | — | Wired Community Software Wwwthreads | 28/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WWWthreads 5.4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the Cat parameter to (1) dosearch.php, (2) postlist.php, (3) showmembers.php, (4) faq_english.php, (5) online.php, (6) login.php, (7) newuser.php, (8) wwwthreads.php,… | |
| Modificada | Alta (7.5) | 6.6% | 💥 Exploit | Perlunity Phpunity Postcard | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL in the gallery_path parameter. | |
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | Bernard Pacques YET Another Community System CMS | 6/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2) categories/category.php, (3) categories/populate.php, (4) comments/populate.php,… | |
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | Bernard Pacques YET Another Community System CMS | 1/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter. | |
| Modificada | Media (5.1) | 2.7% | 💥 Exploit | Interact Learning Community Environment Interact | 30/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[BASE_PATH] parameter in (a) admin/autoprompter.php and (b) includes/common.inc.php, and the (2) CONFIG[LANGUAGE_CPATH] parameter in (c)… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | BlackboardBlackboard Learning AND Community Portal SuiteBlackboard Vista | 23/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML… | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Wired Community Software Wwwthreads | 27/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to inject arbitrary web script or HTML via the week parameter. | |
| Modificada | Media (6.8) | 1.4% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved… | |
| Modificada | Alta (7.5) | 1.3% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | SQL injection vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to execute arbitrary SQL commands via the browse parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Mobescripts Mobile Space Community | 23/6/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in MobeScripts Mobile Space Community 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the uid parameter in the rss page. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Phpcommunitycalendar | 3/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Phpcommunitycalendar | 3/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4)… |