Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 2.6% | — | Yourfreeworld Stylish Text ADS Script | 22/5/2006 | 16/6/2026 | SQL injection vulnerability in tr1.php in YourFreeWorld.com Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly involving an attack vector using advertise.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Jcink Textfilebb | 2/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Jcink.com Textfilebb | 14/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value. | |
| Modificada | Media (5) | 1.4% | — | Text Rider | 26/1/2006 | 16/6/2026 | Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie. | |
| Modificada | Media (5) | 1.7% | — | Text Rider | 26/1/2006 | 16/6/2026 | Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt. | |
| Modificada | Alta (10) | 1.4% | — | Pear Text Password | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds. | |
| Modificada | Alta (7.8) | 12% | 💥 Exploit | Apple SafariApple TexteditApple MAC OS XApple MAC OS X Server | 22/12/2005 | 16/6/2026 | The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag. | |
| Modificada | Media (4.3) | 1.2% | — | Text-e CMS | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters. | |
| Modificada | Alta (7.5) | 2.3% | — | Pstotext | 10/8/2005 | 16/6/2026 | pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file. | |
| Modificada | Baja (2.1) | 0.85% | 💥 Exploit | Stumbleinside Gotext | 3/5/2005 | 16/6/2026 | StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information. | |
| Modificada | Media (5) | 1.2% | — | Text.cgi | 2/5/2005 | 16/6/2026 | text.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument. | |
| Modificada | Media (4.3) | 0.97% | — | Text.cgi | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument. | |
| Modificada | Alta (7.5) | 1.8% | — | Text.cgi | 2/5/2005 | 16/6/2026 | text.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument. | |
| Modificada | Baja (2.1) | 0.40% | — | GNU GettextUbuntu Linux | 9/2/2005 | 16/6/2026 | The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Vilistextum | 10/1/2005 | 16/6/2026 | Buffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted web page. | |
| Modificada | Baja (2.1) | 0.43% | — | Context TexutilAI | 31/12/2004 | 16/6/2026 | TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log. | |
| Modificada | Alta (7.8) | 9.2% | 💥 Exploit | Opentext FirstclassAI | 31/12/2004 | 16/6/2026 | The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search. | |
| Modificada | Alta (10) | 5.2% | — | FTE Text EditorDebian Linux | 4/5/2004 | 16/6/2026 | Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.2% | — | Opentext Firstclass Desktop Client | 20/1/2004 | 16/6/2026 | FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages. | |
| Modificada | Alta (7.5) | 2.1% | — | Textor Webmasters Ltd. Listrec.pl | 11/9/2001 | 16/6/2026 | Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter. | |
| Analizada | Media (5) | 1.5% | — | Opentext Firstclass | 22/8/2001 | 16/6/2026 | Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Matt Wright Textcounter | 24/6/1998 | 16/6/2026 | The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters. |