Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 20% | 💥 Exploit | Microsoft Rich Textbox Control | 11/1/2008 | 16/6/2026 | The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Aspindir Text File Search | 20/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Aspindir Text File Search | 20/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in textfilesearch.aspx in the Text File Search ASP.NET edition allows remote attackers to inject arbitrary web script or HTML via the search field. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Alstrasoft SMS Text Messaging Enterprise | 30/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) q parameter to (a) admin/membersearch.php, or (3) the userid parameter to (b) admin/edituser.php. | |
| Modificada | Media (4.3) | 1.7% | — | Alstrasoft Text ADS Enterprise | 30/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Text Ads Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) r parameter to (a) forgot_uid.php, the (2) query or (3) sk parameter to (b) search_results.php, or (4) the pageId parameter to (c) website_page.php. | |
| Modificada | Media (4.3) | 1.0% | — | Bruce Corkhill WEB WIZ Rich Text Editor | 12/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the rich text editor in Webwiz allows remote attackers to inject arbitrary web script or HTML via URL-encoded HTML composed of a frameset in which a frame has a SRC attribute pointing to a JavaScript document. | |
| Analizada | Media (4.3) | 1.0% | — | Opentext FirstclassOpentext Server AND Internet Services | 1/6/2007 | 16/6/2026 | Centrinity FirstClass 8.3 and earlier, and Server and Internet Services 8.0 and earlier, do not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS) attacks. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Media (4.3) | 1.1% | — | Freetextbox | 8/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FreeTextBox allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag. | |
| Modificada | Media (5) | 2.7% | — | DrupalDrupal Textimage | 1/2/2007 | 16/6/2026 | The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Altdo Convert MP3 MasterAltdo MP3 Record AND Edit Audio MasterAmericanshareware MP3 WAV ConverterAudio Edit Magic+77 | 24/1/2007 | 16/6/2026 | Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple products, allows remote attackers to execute arbitrary code via a long argument to the SetFormatLikeSample function. NOTE: the products include (1) NCTsoft NCTAudioStudio, NCTAudioEditor, and… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Cahier DE Textes | 31/12/2006 | 16/6/2026 | administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Webtext | 31/12/2006 | 16/6/2026 | Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrary PHP code into a script in wt/users/ via the im parameter during a profile edit (edycja) operation, which is then executed via a direct request for this script. | |
| Modificada | Media (6.8) | 1.1% | — | Carsen Klock Textsend | 21/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Carsen Klock TextSend 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) error or (2) success parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Textsend | 21/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter. | |
| Modificada | Alta (7.8) | 1.6% | — | Yourfreeworld Stylish Text ADS Script | 11/12/2006 | 16/6/2026 | tr1.php in Yourfreeworld Stylish Text Ads Script allows remote attackers to obtain the installation path via an invalid id parameter, which leaks the path in an error message. NOTE: this issue might be resultant from CVE-2006-2508. | |
| Modificada | Media (5) | 1.6% | — | Cahier DE Textes | 4/12/2006 | 16/6/2026 | Cahier de texte 2.0 stores sensitive information under the web root, possibly with insufficient access control, which might allow remote attackers to obtain all users' passwords via a direct request for administration/dump.sql. | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Cahier DE Textes | 4/12/2006 | 16/6/2026 | administration/telecharger.php in Cahier de texte 2.0 allows remote attackers to obtain unparsed content (source code) of files via the chemin parameter, as demonstrated using directory traversal sequences to obtain the MySQL username and password from conn_cahier_de_texte.php. NOTE: it is not clear whether the scope… | |
| Modificada | Media (5.1) | 1.6% | — | Pstotext | 26/11/2006 | 16/6/2026 | pstotext before 1.9 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a file name. | |
| Modificada | Media (5) | 1.5% | — | Vilistextum | 3/11/2006 | 16/6/2026 | Memory leak in the push_align function in src/util.c in Vilistextum before 2.6.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the tmp_align variable. NOTE: it is not clear whether this is a vulnerability, due to the functionality of the product. | |
| Modificada | Alta (10) | 1.6% | — | Vilistextum | 3/11/2006 | 16/6/2026 | Multiple off-by-one errors in src/text.c in Vilistextum before 2.6.9 have unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Textpattern | 31/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Cahier DE Textes | 10/10/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Cahier de texte 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) matiere_ID parameter in lire.php or the (2) classe_ID parameter in lire_a_faire.php. | |
| Modificada | Media (5) | 8.0% | 💥 Exploit | Cmtexts | 19/9/2006 | 16/6/2026 | CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to obtain the administrator password. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Idevspot Textads | 13/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in delete.php and (2) the error parameter in error.php. | |
| Modificada | Media (6.5) | 1.0% | — | Subtext | 16/6/2006 | 16/6/2026 | Unspecified vulnerability in the admin login feature in Subtext 1.5, in a multiblog setup, allows remote administrators of one blog to login to another blog. |