Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Scriptdevelopers.net Netclassifieds | 22/6/2007 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en el NetClassifieds Premium Edition permiten a atacantes remotos la inyección de secuencias de comandos web o HTML de su elección a través de vectores sin especificar. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Scriptdevelopers.net Netclassifieds | 22/6/2007 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en NetClassifieds Premium Edition permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro s_user_id en ViewCat.php y otros vectores no especificados. NOTA: los vectores CatID/ViewCat.php, CatID/gallery.php, y ItemNum/ViewItem.php están… | |
| Modificada | Alta (10) | 1.1% | — | Scriptdevelopers.net Netclassifieds | 22/6/2007 | 16/6/2026 | NetClassifieds Premium Edition no utiliza cifrado para (1) contraseñas almacenadas ó (2) datos confidenciales, lo cual podría permitir a atacantes, obtener información confidencial mediante determinados vectores. | |
| Analizada | Media (4.3) | 1.0% | — | Opentext FirstclassOpentext Server AND Internet Services | 1/6/2007 | 16/6/2026 | Centrinity FirstClass 8.3 y versiones anteriores y Server e Internet Services 8.0 y versiones anteriores, no manejan adecuadamente una URL con un caracter nulo ("%00") lo que permite a atacantes remotos llevar a cabo un ataque de secuencias de comandos en sitios cruzados (XSS). NOTA: la procedencia de esta información… | |
| Modificada | Alta (7.2) | 0.36% | — | TCL TK | 29/5/2007 | 16/6/2026 | Desbordamiento de búfer en tcl/win/tclWinReg.c en Tcl (Tcl/Tk) anterior a 8.5a6 permite a usuarios locales obtener privilegios mediante rutas de clave de registro largas. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Dotclear | 12/4/2007 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en DotClear versiones anteriores a 1.2.6 permite a atacantes remotos inyectar scripts web o HTML de su elección a través de (1) el parámetro post_id en ecrire/trackback.php ó (2) el parámetro tool_url en tools/thememng/index.php. NOTA:… | |
| Modificada | Media (5) | 2.3% | — | Dotclear | 31/7/2006 | 16/6/2026 | DotClear permite a atacantes remotos obtener información confidencial mediante una petición directa de (1) edit_cat.php, (2) index.php, (3) edit_link.php en ecrire/tools/blogroll/; (4) syslog/index.php, (5) thememng/index.php, (6) toolsmng/index.php, (7) utf8convert/index.php en /ecrire/tools/; (8)… | |
| Modificada | Media (5.1) | 3.2% | 💥 Exploit | Dotclear | 6/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a FTP URL in the blog_dc_path parameter, which passes file_exists() and is_dir() tests on PHP 5. | |
| Modificada | Media (5) | 1.2% | 💥 Exploit | Triggertg Tclanportal | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Scriptdevelopers.net Netclassifieds | 3/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c)… | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Dotclear | 2/12/2005 | 16/6/2026 | SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd parameter in a cookie. | |
| Modificada | Alta (10) | 1.6% | — | Dotclear | 1/12/2005 | 16/6/2026 | Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Centrinity Firstclass Desktop Client | 2/5/2005 | 16/6/2026 | OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark. | |
| Modificada | Alta (7.8) | 9.2% | 💥 Exploit | Opentext FirstclassAI | 31/12/2004 | 16/6/2026 | The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availability loss) via a large number of POST requests to /Search. | |
| Modificada | Alta (7.5) | 2.2% | — | Opentext Firstclass Desktop Client | 20/1/2004 | 16/6/2026 | FirstClass Desktop Client 7.1 permite a atacantes remotos ejecutar instrucciones arbitrarias mediante hiperenlaces en mensajes FirstClass RTF. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Centrinity FirstclassAI | 31/12/2003 | 16/6/2026 | Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the URL and checking all of the search option checkboxes and leaving the text field blank, which will return all files in the searched directory. | |
| Analizada | Media (5) | 1.5% | — | Opentext Firstclass | 22/8/2001 | 16/6/2026 | Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Centrinity Firstclass Intranet Server | 27/6/2000 | 16/6/2026 | FirstClass Internet Services server 5.770, and other versions before 6.1, allows remote attackers to cause a denial of service by sending an email with a long To: mail header. | |
| Modificada | Media (4.6) | 0.33% | — | Softarc Firstclass Internet Server | 30/8/1999 | 16/6/2026 | E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled. |