Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)2.6%—Yourfreeworld Stylish Text ADS Script22/5/200616/6/2026
SQL injection vulnerability in tr1.php in YourFreeWorld.com Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly involving an attack vector using advertise.php.
ModificadaMedia (4.3)1.9%💥 ExploitJcink Textfilebb2/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags.
ModificadaMedia (4.3)1.9%💥 ExploitJcink.com Textfilebb14/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value.
ModificadaMedia (5)1.4%—Text Rider26/1/200616/6/2026
Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.
ModificadaMedia (5)1.7%—Text Rider26/1/200616/6/2026
Text Rider 2.4 stores sensitive data in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing data/userlist.txt.
ModificadaAlta (10)1.4%—Pear Text Password31/12/200516/6/2026
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds.
ModificadaAlta (7.8)12%💥 ExploitApple SafariApple TexteditApple MAC OS XApple MAC OS X Server22/12/200516/6/2026
The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.
ModificadaMedia (4.3)1.2%—Text-e CMS22/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Text-e 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters.
ModificadaAlta (7.5)2.3%—Pstotext10/8/200516/6/2026
pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.
ModificadaBaja (2.1)0.85%💥 ExploitStumbleinside Gotext3/5/200516/6/2026
StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.
ModificadaMedia (5)1.2%—Text.cgi2/5/200516/6/2026
text.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
ModificadaMedia (4.3)0.97%—Text.cgi2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.
ModificadaAlta (7.5)1.8%—Text.cgi2/5/200516/6/2026
text.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.
ModificadaBaja (2.1)0.40%—GNU GettextUbuntu Linux9/2/200516/6/2026
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
ModificadaAlta (10)12%💥 ExploitVilistextum10/1/200516/6/2026
Buffer overflow in the get_attr function in html.c for vilistextum 2.6.6 allows remote attackers to execute arbitrary code via a crafted web page.
ModificadaBaja (2.1)0.43%—Context TexutilAI31/12/200416/6/2026
TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.
ModificadaAlta (7.8)9.2%💥 ExploitOpentext FirstclassAI31/12/200416/6/2026
The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search.
ModificadaAlta (10)5.2%—FTE Text EditorDebian Linux4/5/200416/6/2026
Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.
ModificadaAlta (7.5)2.2%—Opentext Firstclass Desktop Client20/1/200416/6/2026
FirstClass Desktop Client 7.1 allows remote attackers to execute arbitrary commands via hyperlinks in FirstClass RTF messages.
ModificadaAlta (7.5)2.1%—Textor Webmasters Ltd. Listrec.pl11/9/200116/6/2026
Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter.
AnalizadaMedia (5)1.5%—Opentext Firstclass22/8/200116/6/2026
Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.
ModificadaAlta (10)12%💥 ExploitMatt Wright Textcounter24/6/199816/6/2026
The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.
Orbitaley — Vulnerabilidades