Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 88% | 💥 Exploit | Symantec AntivirusSymantec Antivirus Central Quarantine ServerSymantec Client SecuritySymantec Endpoint Protection+1 | 29/4/2009 | 16/6/2026 | El LANDesk Common Base Agent (CBA) de Intel en Alert Management System 2 (AMS2) de Symantec, tal y como es usado en System Center (SSS) de Symantec; AntiVirus Server de Symantec; AntiVirus Central Quarantine Server de Symantec; Symantec AntiVirus (SAV) Corporate Edition versiones 9 anteriores a 9.0 MR7, versiones 10.0… | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Castillocentral Ccleague | 18/11/2008 | 16/6/2026 | admin.php en CCleague Pro v1.2 permite a atacantes remotos evitar la autenticación estableciendo el valor de una cookie a admin. | |
| Modificada | Media (6.8) | 0.98% | 💥 Exploit | Castillocentral Ccleague | 18/11/2008 | 16/6/2026 | Vulnerabilidad de inyección SQL en admin.php en CCleague Pro 1.2 permite a atacantes remotos ejecutar comandos arbitrarios SQL a través del parámetro U. | |
| Modificada | Alta (7.5) | 1.8% | — | Phpcentral Poll Script | 14/8/2007 | 16/6/2026 | Múltiples vulnerabilidades de inclusión remota de archivos PHP en PHPCentral Poll Script versión 1.0, permiten a atacantes remotos ejecutar código PHP arbitrario por medio de una URL en el parámetro _SERVER[DOCUMENT_ROOT] en los archivos (1) poll.php y (2) pollarchive.php. NOTA: un tercero confiable declara que este… | |
| Modificada | Alta (7.5) | 2.0% | — | Phpcentral Login | 14/8/2007 | 16/6/2026 | Una vulnerabilidad de inclusión remota de archivos PHP en el archivo include.php en PHPCentral Login versión 1.0, permite a atacantes remotos ejecutar código PHP arbitrario por medio de una URL en el parámetro _SERVER[DOCUMENT_ROOT]. NOTA: un tercero cuestiona esta vulnerabilidad debido a la naturaleza especial de la… | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Ubbcentral Ubb.threads | 11/4/2007 | 16/6/2026 | Vulnerabilidad de inyección SQL en ubbthreads.php en Groupee UBB.threads 6.1.1 y anteriores permite a atacantes remotos ejecutar comandos SQL a través del parámetro C. | |
| Modificada | Alta (9) | 4.5% | 💥 Exploit | Centrality Communications Pa168 Chipset | 26/1/2007 | 16/6/2026 | La consola del web admin implementada por Centrality Communications (también conocido como Aredfox) PA168 chipset y firmware 1.54 y anteriores, en la manera prevista por varios teléfonos del IP, no requiere contraseñas o validación de tokens cuando se usa HTTP, lo cual permite a atacantes remotos conetar a un… | |
| Modificada | Media (6.8) | 1.3% | — | Db-central CMSDb-central Enterprise CMS | 20/10/2006 | 16/6/2026 | Vulnerabilida de secuencias de comandos en sitios cruzados en la funcionalidad de búsqueda en db-central (dbc) Enterprise CMS y db-central CMS permite a un atacante remoto inyectar secuencias de comandos web o HTML a través del parámetro needle. NOTA: el origen de esta información es desconocido; los detalles se… | |
| Modificada | Alta (7.5) | 1.6% | — | Ubbcentral Ubb.threads | 3/10/2006 | 16/6/2026 | Múltiples vulnerabilidades PHP de inclusión remota de archivo en ubbt.inc.php en Groupee UBB.threads 6.5.1.1 permite a un atacante remoto ejecutar código PHP de su elección a través de un URL en los parámetros 1) GLOBALS[thispath] o (2) GLOBALS[configdir]. | |
| Modificada | Media (5.1) | 2.2% | 💥 Exploit | Ubbcentral Ubb.threads | 3/10/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección de código directo estático en Groupee UBB.threads 6.5.1.1 permite a un atacante remoto (1) inyectar código PHP a través de un parámetro array theme[] a admin/doedittheme.php, el cual se inyecta dentro de includes/theme.inc.php; (2) inyectar código PHP a través del parámetro… | |
| Modificada | Media (5) | 1.5% | — | Ubbcentral Ubb.threads | 3/10/2006 | 16/6/2026 | Groupee UBB.threads 6.5.1.1 permite a un atacante remoto obtener información sensible a través de una petición directa para cron/php/subscriptions.php, lo cual revela la ruta en un mensaje de error. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Ubbcentral Ubb.threads | 2/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords. | |
| Modificada | Alta (7.6) | 7.3% | 💥 Exploit | Zipcentral | 1/6/2006 | 16/6/2026 | Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename. | |
| Modificada | Media (5.1) | 2.5% | 💥 Exploit | Ubbcentral Ubb.threads | 30/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters. | |
| Modificada | Media (5.1) | 7.9% | 💥 Exploit | Ubbcentral Ubb.threads | 24/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter. | |
| Modificada | Media (5) | 0.96% | — | Ubbcentral Ubb.threads | 28/3/2006 | 16/6/2026 | SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Ubbcentral Ubb.threads | 4/2/2006 | 16/6/2026 | SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter. | |
| Modificada | Alta (7.5) | 5.6% | — | Symantec Veritas Storage ExecSymantec Veritas Storagecentral | 20/9/2005 | 16/6/2026 | Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls. | |
| Modificada | Media (6.8) | 1.5% | — | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to… | |
| Modificada | Media (6.5) | 0.96% | — | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag. | |
| Modificada | Media (5) | 1.3% | — | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to… | |
| Modificada | Media (5) | 1.3% | — | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Ubbcentral Ubb.threads | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Ubbcentral Ubb.threads | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter. |