Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
687 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Phplibre Registrotl | 17/10/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en main.php en registroTL permite a atacantes remotos ejecutar código PHP de su elección mediante una ftp:// URL en el parámetro page. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Mamboxchange Extended Registration | 12/10/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en registration_detailed.inc.php en Mark Van Bellen Registro Detallado de Usuario (com_registration_detailed), también conocido como regdetailed 4.1 y versiones anteriores, permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el… | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Cescripts Event Registration 2checkoutCescripts Event Registration CorporateCescripts Event Registration PaypalCescripts Event Registration Rsvp | 16/6/2006 | 16/6/2026 | Vulnerabilidad de ejecución de comandos en sitios cruzados (Cross-site scripting (XSS)) en el Registro de Eventos (Event Registration) que permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) event_id para ver-evento-details.php o (2) el parámetro select_events para… | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco User Registration ToolCisco Wireless LAN Solution EngineCiscoworks 2000 Service Management SolutionCisco Hosting Solution Engine+1 | 21/4/2006 | 16/6/2026 | Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell… | |
| Modificada | Alta (7.5) | 1.5% | — | PHP Gift Registry Phpgiftreg | 17/1/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters. | |
| Modificada | Media (5) | 1.2% | — | Cisco CNS Network Registrar | 10/1/2005 | 16/6/2026 | Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets. | |
| Modificada | Media (5) | 1.6% | — | Cisco CNS Network Registrar | 10/1/2005 | 16/6/2026 | The lock manager in Cisco CNS Network Registrar 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (process crash) via a certain "unexpected packet sequence." | |
| Modificada | Alta (7.5) | 29% | 💥 Exploit | David Maciejak Athena WEB Registration | 31/12/2004 | 16/6/2026 | athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters in the pass parameter. | |
| Modificada | Media (4.3) | 1.4% | — | PHP Gift Registry Phpgiftreg | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP Gift Registry 1.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter to (1) event.php or (2) index.php. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. |