Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.5% | — | John LIM Adodb Date Library | 25/9/2006 | 16/6/2026 | The Date Library in John Lim ADOdb Library for PHP allows remote attackers to obtain sensitive information via a direct request for (1) server.php, (2) adodb-errorpear.inc.php, (3) adodb-iterator.inc.php, (4) adodb-pear.inc.php, (5) adodb-perf.inc.php, (6) adodb-xmlschema.inc.php, and (7) adodb.inc.php; files in… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Bosdev Bosdates | 1/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter. | |
| Modificada | Media (6.8) | 1.7% | — | Darrens 5-dollar Script Archive Osdate | 21/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in showprofile.php in Darren's $5 Script Archive osDate 1.1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the onerror attribute in an HTML IMG tag with a non-existent source file in txtcomment parameter, which is used when posting a comment. | |
| Modificada | Media (5) | 1.2% | — | Darrens 5-dollar Script Archive Osdate | 21/7/2006 | 16/6/2026 | Darren's $5 Script Archive osDate 1.1.7 and earlier allows users to boost their own ratings via a txtrating parameter with a score greater than the intended maximum of 10. | |
| Modificada | Alta (7.5) | 1.8% | — | Lumension Patchlink Update ServerNovell Zenworks | 7/7/2006 | 16/6/2026 | SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Lumension Patchlink Update ServerNovell Zenworks | 7/7/2006 | 16/6/2026 | FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List,… | |
| Modificada | Media (5) | 2.7% | — | Lumension Patchlink Update ServerNovell Zenworks | 7/7/2006 | 16/6/2026 | Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to… | |
| Modificada | Media (5) | 1.4% | — | Datetopia Dating Agent PRO | 28/6/2006 | 16/6/2026 | requirements.php in Dating Agent PRO 4.7.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function. | |
| Modificada | Baja (2.6) | 1.2% | — | Datetopia Dating Agent PRO | 28/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in (1) webmaster/index.php and (2) search.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Datetopia Dating Agent PRO | 28/6/2006 | 16/6/2026 | SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php. | |
| Modificada | Media (5.8) | 1.3% | — | Ifdate.com Ifdate | 30/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in iFdate 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password fields, or certain other input text boxes. | |
| Modificada | Media (6.8) | 0.39% | — | Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+2 | 19/4/2006 | 16/6/2026 | Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program. | |
| Modificada | Media (4.3) | 1.4% | — | Datenbank Module | 9/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter to (1) info_db.php or (2) database.php. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Datenbank ModuleWoltlab Burning Board | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php. | |
| Modificada | Media (4.3) | 4.2% | 💥 Exploit | Fatwire Updateengine | 29/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Bosdev Bosdates | 30/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parameters. | |
| Modificada | Alta (7.5) | 2.7% | — | Ipupdate | 23/11/2005 | 16/6/2026 | Multiple buffer overflows in IPUpdate 1.1 might allow attackers to execute arbitrary code via (1) memmcat in the memm module or (2) certain TSIG format records. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Datenbank Module | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Datenbank Module | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 3.1% | — | Xzabite Dyndnsupdate | 2/5/2005 | 16/6/2026 | Multiple buffer overflows in Xzabite DYNDNSUpdate 0.6.15 and earlier, including the ipcheck function in dyndnsupdate.c, allow remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (10) | 3.8% | — | Angus Mackay Ez-ipupdateDebian LinuxGentoo Linux | 9/2/2005 | 16/6/2026 | Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Bosdev Bosdates | 23/11/2004 | 16/6/2026 | SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System WorksSymantec Windows Liveupdate | 3/2/2004 | 16/6/2026 | The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges. | |
| Modificada | Baja (2.1) | 0.29% | — | Angus Mackay Ez-ipupdate | 31/12/2003 | 16/6/2026 | ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file. | |
| Modificada | Media (4.6) | 0.82% | 💥 Exploit | Datev Nutzungskontrolle | 31/12/2003 | 16/6/2026 | DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle. |