Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.5% | — | DokeosDokeos Community Release | 10/5/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allow remote attackers to execute arbitrary PHP code via a URL in the (1) rootSys and (2) clarolineRepositorySys parameters, and possibly the (3) lang_path, (4)… | |
| Modificada | Media (6.4) | 1.4% | — | Invision Power Services Invision Community Blog | 9/5/2006 | 16/6/2026 | SQL injection vulnerability in the do_mmod function in mod.php in Invision Community Blog (ICB) 1.1.2 final through 1.2 allows remote attackers with moderator privileges to execute arbitrary SQL commands via the selectedbids parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Creative Software Community Portal | 9/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4)… | |
| Modificada | Baja (2.1) | 1.6% | — | Cisco Unity Express SoftwareCisco Unity Express | 4/5/2006 | 16/6/2026 | Unspecified vulnerability in the HTTP management interface in Cisco Unity Express (CUE) 2.2(2) and earlier, when running on any CUE Advanced Integration Module (AIM) or Network Module (NM), allows remote authenticated attackers to reset the password for any user with an expired password. | |
| Modificada | Media (4.3) | 1.2% | — | Community Architect Guestbook | 25/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed by fsguestbook.html. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (6.4) | 1.3% | — | Wired Community Software Wwwthreads | 21/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in WWWThreads RC 3 allow remote attackers to execute arbitrary SQL commands via (1) the forumreferrer cookie to register.php and (2) the messages parameter in message_list.php. | |
| Modificada | Media (4.3) | 1.5% | — | Communityserver.org Community Server | 4/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: this candidate does not contain any actionable or distinguishing information. Perhaps it should not be included in CVE. NOTE: the provenance of this… | |
| Modificada | Media (5) | 2.4% | — | Cisco Application AND Content Networking SoftwareCisco ATACisco Subscriber Edge Services ManagerCisco IP Phone 7902+3 | 31/12/2005 | 16/6/2026 | Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect offset. | |
| Modificada | Media (4.3) | 1.2% | — | Citysoft Community Enterprise | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in CitySoft Community Enterprise 4.x allows remote attackers to inject arbitrary web script or HTML via the (1) presentationSite, (2) docPublishYear, (3) docDescription, (4) publishState, (5) docAuthor, (6) docTitle, (7) subTopic, (8) topic, (9) topicRadio, (10)… | |
| Modificada | Alta (7.5) | 1.3% | — | Citysoft Community Enterprise | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in CitySoft Community Enterprise 4.x allows remote attackers to execute arbitrary SQL commands via the (1) nodeID, (2) pageID, (3) ID, and (4) parentid parameter to index.cfm; and (5) documentFormatId parameter to document/docWindow.cfm. | |
| Modificada | Media (6.4) | 1.4% | — | Citysoft Community Enterprise | 20/12/2005 | 16/6/2026 | CitySoft Community Enterprise 4.x allows remote attackers to obtain the full path of the server via an invalid (1) fuseaction parameter to index.cfm and (2) documentid parameter to document/docWindow.cfm. | |
| Modificada | Media (5.1) | 4.1% | — | Abisource Community Abiword | 23/10/2005 | 16/6/2026 | Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions… | |
| Modificada | Alta (7.5) | 4.6% | — | Abisource Community Abiword | 28/9/2005 | 16/6/2026 | Stack-based buffer overflow in AbiWord before 2.2.10 allows attackers to execute arbitrary code via the RTF import mechanism. | |
| Modificada | Media (4.3) | 1.3% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the LocationID parameter to (1) thankyou.php or (2) day.php, font parameter to (3) calDaily.php, (4) calMonthly.php, (5) calMonthlyP.php,… | |
| Modificada | Alta (7.5) | 1.8% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via the (1) login field in login.php or (2) LocationID parameter to week.php. | |
| Modificada | Media (4.3) | 0.97% | — | Telligent Systems Community Server Forums | 5/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Community Link PRO WEB Editor | 5/7/2005 | 16/6/2026 | login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Invision Power Services Invision Community Blog | 9/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action. | |
| Modificada | Media (4.3) | 0.46% | — | Invisioncommunity Gallery | 9/6/2005 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions. | |
| Modificada | Media (4.3) | 1.2% | — | Invision Power Services Invision Community Blog | 9/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (7.5) | 1.3% | — | Invision Power Services Invision Community Blog | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco Unity Server | 15/12/2004 | 16/6/2026 | Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages. | |
| Modificada | Baja (2.1) | 0.47% | — | Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Admin-cd FOR FirewallSuse Linux Connectivity Server+13 | 6/8/2004 | 16/6/2026 | El controlador e1000 del kernel de Linux 2.4.26 y anteriores no inicializa la memoria antes de usarla, lo que permite a usuarios locales leer porciones de la memoria del kernel. NOTA: Este problema ha sido originalmente descrito incorrectamente por otras fuentes como un "desbordamiento de búfer". |