Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.5%—John LIM Adodb Date Library25/9/200616/6/2026
The Date Library in John Lim ADOdb Library for PHP allows remote attackers to obtain sensitive information via a direct request for (1) server.php, (2) adodb-errorpear.inc.php, (3) adodb-iterator.inc.php, (4) adodb-pear.inc.php, (5) adodb-perf.inc.php, (6) adodb-xmlschema.inc.php, and (7) adodb.inc.php; files in…
ModificadaAlta (7.5)2.5%💥 ExploitBosdev Bosdates1/8/200616/6/2026
PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter.
ModificadaMedia (6.8)1.7%—Darrens 5-dollar Script Archive Osdate21/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in showprofile.php in Darren's $5 Script Archive osDate 1.1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the onerror attribute in an HTML IMG tag with a non-existent source file in txtcomment parameter, which is used when posting a comment.
ModificadaMedia (5)1.2%—Darrens 5-dollar Script Archive Osdate21/7/200616/6/2026
Darren's $5 Script Archive osDate 1.1.7 and earlier allows users to boost their own ratings via a txtrating parameter with a score greater than the intended maximum of 10.
ModificadaAlta (7.5)1.8%—Lumension Patchlink Update ServerNovell Zenworks7/7/200616/6/2026
SQL injection vulnerability in checkprofile.asp in (1) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (2) Novell ZENworks 6.2 SR1 and earlier, allows remote attackers to execute arbitrary SQL commands via the agentid parameter.
ModificadaAlta (7.5)2.3%—Lumension Patchlink Update ServerNovell Zenworks7/7/200616/6/2026
FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List,…
ModificadaMedia (5)2.7%—Lumension Patchlink Update ServerNovell Zenworks7/7/200616/6/2026
Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to…
ModificadaMedia (5)1.4%—Datetopia Dating Agent PRO28/6/200616/6/2026
requirements.php in Dating Agent PRO 4.7.1 allows remote attackers to obtain sensitive information via a direct request, which calls the phpinfo function.
ModificadaBaja (2.6)1.2%—Datetopia Dating Agent PRO28/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to inject arbitrary web script or HTML via the login parameter in (1) webmaster/index.php and (2) search.php.
ModificadaAlta (7.5)1.2%—Datetopia Dating Agent PRO28/6/200616/6/2026
SQL injection vulnerability in Dating Agent PRO 4.7.1 allows remote attackers to execute arbitrary SQL commands via the (1) pid parameter in picture.php, (2) mid parameter in mem.php, and the (3) sex and (4) relationship parameters in search.php.
ModificadaMedia (5.8)1.3%—Ifdate.com Ifdate30/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in iFdate 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) username, (2) password fields, or certain other input text boxes.
ModificadaMedia (6.8)0.39%—Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+219/4/200616/6/2026
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.
ModificadaMedia (4.3)1.4%—Datenbank Module9/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allow remote attackers to inject arbitrary web script or HTML via the fileid parameter to (1) info_db.php or (2) database.php.
ModificadaAlta (7.5)2.4%💥 ExploitDatenbank ModuleWoltlab Burning Board9/3/200616/6/2026
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.
ModificadaMedia (4.3)4.2%💥 ExploitFatwire Updateengine29/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameters.
ModificadaAlta (7.5)1.2%💥 ExploitBosdev Bosdates30/11/200516/6/2026
Multiple SQL injection vulnerabilities in calendar.php in BosDates 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) category parameters.
ModificadaAlta (7.5)2.7%—Ipupdate23/11/200516/6/2026
Multiple buffer overflows in IPUpdate 1.1 might allow attackers to execute arbitrary code via (1) memmcat in the memm module or (2) certain TSIG format records.
ModificadaAlta (7.5)1.0%💥 ExploitDatenbank Module2/5/200516/6/2026
SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.7%💥 ExploitDatenbank Module2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)3.1%—Xzabite Dyndnsupdate2/5/200516/6/2026
Multiple buffer overflows in Xzabite DYNDNSUpdate 0.6.15 and earlier, including the ipcheck function in dyndnsupdate.c, allow remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors.
ModificadaAlta (10)3.8%—Angus Mackay Ez-ipupdateDebian LinuxGentoo Linux9/2/200516/6/2026
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
ModificadaMedia (5)2.6%💥 ExploitBosdev Bosdates23/11/200416/6/2026
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.
ModificadaAlta (7.2)0.41%—Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System WorksSymantec Windows Liveupdate3/2/200416/6/2026
The GUI functionality for an interactive session in Symantec LiveUpdate 1.70.x through 1.90.x, as used in Norton Internet Security 2001 through 2004, SystemWorks 2001 through 2004, and AntiVirus and Norton AntiVirus Pro 2001 through 2004, AntiVirus for Handhelds v3.0, allows local users to gain SYSTEM privileges.
ModificadaBaja (2.1)0.29%—Angus Mackay Ez-ipupdate31/12/200316/6/2026
ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file.
ModificadaMedia (4.6)0.82%💥 ExploitDatev Nutzungskontrolle31/12/200316/6/2026
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users to bypass access restrictions by importing NukoInfo values in certain DATEV keys, which disables Nutzungskontrolle.
Orbitaley — Vulnerabilidades