Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Scriptdevelopers.net Netclassifieds22/6/200716/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en el NetClassifieds Premium Edition permiten a atacantes remotos la inyección de secuencias de comandos web o HTML de su elección a través de vectores sin especificar.
ModificadaAlta (7.5)2.1%💥 ExploitScriptdevelopers.net Netclassifieds22/6/200716/6/2026
Múltiples vulnerabilidades de inyección SQL en NetClassifieds Premium Edition permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro s_user_id en ViewCat.php y otros vectores no especificados. NOTA: los vectores CatID/ViewCat.php, CatID/gallery.php, y ItemNum/ViewItem.php están…
ModificadaAlta (10)1.1%—Scriptdevelopers.net Netclassifieds22/6/200716/6/2026
NetClassifieds Premium Edition no utiliza cifrado para (1) contraseñas almacenadas ó (2) datos confidenciales, lo cual podría permitir a atacantes, obtener información confidencial mediante determinados vectores.
AnalizadaMedia (4.3)1.0%—Opentext FirstclassOpentext Server AND Internet Services1/6/200716/6/2026
Centrinity FirstClass 8.3 y versiones anteriores y Server e Internet Services 8.0 y versiones anteriores, no manejan adecuadamente una URL con un caracter nulo ("%00") lo que permite a atacantes remotos llevar a cabo un ataque de secuencias de comandos en sitios cruzados (XSS). NOTA: la procedencia de esta información…
ModificadaAlta (7.2)0.36%—TCL TK29/5/200716/6/2026
Desbordamiento de búfer en tcl/win/tclWinReg.c en Tcl (Tcl/Tk) anterior a 8.5a6 permite a usuarios locales obtener privilegios mediante rutas de clave de registro largas.
ModificadaMedia (4.3)2.0%💥 ExploitDotclear12/4/200716/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en DotClear versiones anteriores a 1.2.6 permite a atacantes remotos inyectar scripts web o HTML de su elección a través de (1) el parámetro post_id en ecrire/trackback.php ó (2) el parámetro tool_url en tools/thememng/index.php. NOTA:…
ModificadaMedia (5)2.3%—Dotclear31/7/200616/6/2026
DotClear permite a atacantes remotos obtener información confidencial mediante una petición directa de (1) edit_cat.php, (2) index.php, (3) edit_link.php en ecrire/tools/blogroll/; (4) syslog/index.php, (5) thememng/index.php, (6) toolsmng/index.php, (7) utf8convert/index.php en /ecrire/tools/; (8)…
ModificadaMedia (5.1)3.2%💥 ExploitDotclear6/6/200616/6/2026
PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a FTP URL in the blog_dc_path parameter, which passes file_exists() and is_dir() tests on PHP 5.
ModificadaMedia (5)1.2%💥 ExploitTriggertg Tclanportal31/12/200516/6/2026
SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.
ModificadaAlta (7.5)2.7%💥 ExploitScriptdevelopers.net Netclassifieds3/12/200516/6/2026
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c)…
ModificadaAlta (7.5)1.4%💥 ExploitDotclear2/12/200516/6/2026
SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie.
ModificadaAlta (10)1.6%—Dotclear1/12/200516/6/2026
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.
ModificadaAlta (7.5)2.2%—Centrinity Firstclass Desktop Client2/5/200516/6/2026
OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.
ModificadaAlta (7.8)9.2%💥 ExploitOpentext FirstclassAI31/12/200416/6/2026
The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search.
ModificadaAlta (7.5)2.2%—Opentext Firstclass Desktop Client20/1/200416/6/2026
FirstClass Desktop Client 7.1 permite a atacantes remotos ejecutar instrucciones arbitrarias mediante hiperenlaces en mensajes FirstClass RTF.
ModificadaMedia (5)3.4%💥 ExploitCentrinity FirstclassAI31/12/200316/6/2026
Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory.
AnalizadaMedia (5)1.5%—Opentext Firstclass22/8/200116/6/2026
Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.
ModificadaMedia (5)3.1%💥 ExploitCentrinity Firstclass Intranet Server27/6/200016/6/2026
FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header.
ModificadaMedia (4.6)0.33%—Softarc Firstclass Internet Server30/8/199916/6/2026
E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.
Orbitaley — Vulnerabilidades