Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)88%💥 ExploitSymantec AntivirusSymantec Antivirus Central Quarantine ServerSymantec Client SecuritySymantec Endpoint Protection+129/4/200916/6/2026
El LANDesk Common Base Agent (CBA) de Intel en Alert Management System 2 (AMS2) de Symantec, tal y como es usado en System Center (SSS) de Symantec; AntiVirus Server de Symantec; AntiVirus Central Quarantine Server de Symantec; Symantec AntiVirus (SAV) Corporate Edition versiones 9 anteriores a 9.0 MR7, versiones 10.0…
ModificadaMedia (6.8)2.2%💥 ExploitCastillocentral Ccleague18/11/200816/6/2026
admin.php en CCleague Pro v1.2 permite a atacantes remotos evitar la autenticación estableciendo el valor de una cookie a admin.
ModificadaMedia (6.8)0.98%💥 ExploitCastillocentral Ccleague18/11/200816/6/2026
Vulnerabilidad de inyección SQL en admin.php en CCleague Pro 1.2 permite a atacantes remotos ejecutar comandos arbitrarios SQL a través del parámetro U.
ModificadaAlta (7.5)1.8%—Phpcentral Poll Script14/8/200716/6/2026
Múltiples vulnerabilidades de inclusión remota de archivos PHP en PHPCentral Poll Script versión 1.0, permiten a atacantes remotos ejecutar código PHP arbitrario por medio de una URL en el parámetro _SERVER[DOCUMENT_ROOT] en los archivos (1) poll.php y (2) pollarchive.php. NOTA: un tercero confiable declara que este…
ModificadaAlta (7.5)2.0%—Phpcentral Login14/8/200716/6/2026
Una vulnerabilidad de inclusión remota de archivos PHP en el archivo include.php en PHPCentral Login versión 1.0, permite a atacantes remotos ejecutar código PHP arbitrario por medio de una URL en el parámetro _SERVER[DOCUMENT_ROOT]. NOTA: un tercero cuestiona esta vulnerabilidad debido a la naturaleza especial de la…
ModificadaAlta (7.5)0.98%💥 ExploitUbbcentral Ubb.threads11/4/200716/6/2026
Vulnerabilidad de inyección SQL en ubbthreads.php en Groupee UBB.threads 6.1.1 y anteriores permite a atacantes remotos ejecutar comandos SQL a través del parámetro C.
ModificadaAlta (9)4.5%💥 ExploitCentrality Communications Pa168 Chipset26/1/200716/6/2026
La consola del web admin implementada por Centrality Communications (también conocido como Aredfox) PA168 chipset y firmware 1.54 y anteriores, en la manera prevista por varios teléfonos del IP, no requiere contraseñas o validación de tokens cuando se usa HTTP, lo cual permite a atacantes remotos conetar a un…
ModificadaMedia (6.8)1.3%—Db-central CMSDb-central Enterprise CMS20/10/200616/6/2026
Vulnerabilida de secuencias de comandos en sitios cruzados en la funcionalidad de búsqueda en db-central (dbc) Enterprise CMS y db-central CMS permite a un atacante remoto inyectar secuencias de comandos web o HTML a través del parámetro needle. NOTA: el origen de esta información es desconocido; los detalles se…
ModificadaAlta (7.5)1.6%—Ubbcentral Ubb.threads3/10/200616/6/2026
Múltiples vulnerabilidades PHP de inclusión remota de archivo en ubbt.inc.php en Groupee UBB.threads 6.5.1.1 permite a un atacante remoto ejecutar código PHP de su elección a través de un URL en los parámetros 1) GLOBALS[thispath] o (2) GLOBALS[configdir].
ModificadaMedia (5.1)2.2%💥 ExploitUbbcentral Ubb.threads3/10/200616/6/2026
Múltiples vulnerabilidades de inyección de código directo estático en Groupee UBB.threads 6.5.1.1 permite a un atacante remoto (1) inyectar código PHP a través de un parámetro array theme[] a admin/doedittheme.php, el cual se inyecta dentro de includes/theme.inc.php; (2) inyectar código PHP a través del parámetro…
ModificadaMedia (5)1.5%—Ubbcentral Ubb.threads3/10/200616/6/2026
Groupee UBB.threads 6.5.1.1 permite a un atacante remoto obtener información sensible a través de una petición directa para cron/php/subscriptions.php, lo cual revela la ruta en un mensaje de error.
ModificadaMedia (4.3)2.3%💥 ExploitUbbcentral Ubb.threads2/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.
ModificadaAlta (7.6)7.3%💥 ExploitZipcentral1/6/200616/6/2026
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.
ModificadaMedia (5.1)2.5%💥 ExploitUbbcentral Ubb.threads30/5/200616/6/2026
PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters.
ModificadaMedia (5.1)7.9%💥 ExploitUbbcentral Ubb.threads24/5/200616/6/2026
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.
ModificadaMedia (5)0.96%—Ubbcentral Ubb.threads28/3/200616/6/2026
SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter.
ModificadaAlta (7.5)1.3%💥 ExploitUbbcentral Ubb.threads4/2/200616/6/2026
SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter.
ModificadaAlta (7.5)5.6%—Symantec Veritas Storage ExecSymantec Veritas Storagecentral20/9/200516/6/2026
Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls.
ModificadaMedia (6.8)1.5%—Ubbcentral Ubb.threads29/6/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to…
ModificadaMedia (6.5)0.96%—Ubbcentral Ubb.threads29/6/200516/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.
ModificadaMedia (5)1.3%—Ubbcentral Ubb.threads29/6/200516/6/2026
Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.
ModificadaAlta (7.5)1.2%💥 ExploitUbbcentral Ubb.threads29/6/200516/6/2026
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to…
ModificadaMedia (5)1.3%—Ubbcentral Ubb.threads29/6/200516/6/2026
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.
ModificadaAlta (7.5)1.2%—Ubbcentral Ubb.threads2/5/200516/6/2026
SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.
ModificadaMedia (4.3)2.2%💥 ExploitUbbcentral Ubb.threads31/12/200416/6/2026
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter.