Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%💥 Exploit8pixel.net Simple Blog18/1/200616/6/2026
Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.
ModificadaMedia (5.1)19%💥 ExploitMicrosoft Visual Studio .net12/1/200616/6/2026
By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.
ModificadaAlta (7.5)1.5%—Jasio.net Ragnarok Online Control Panel31/12/200516/6/2026
functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a trailing "/login.php" PHP_SELF value, which is not properly handled by the CHECK_AUTH function.
ModificadaMedia (4.3)1.7%💥 ExploitFocalmedia.net Sitenet BBS17/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SiteNet BBS 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pg, (2) tid, (3) cid, and (4) fid parameters to netboardr.cgi, or (5) cid parameter to search.cgi.
ModificadaMedia (4.3)1.7%—Ideal Science Ideal Bb.net8/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Ideal BB.NET 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) forumID, (2) boardID, and (3) topicRepeater1-p parameters in topics.aspx, (4) boardID parameter in categoryindex.aspx, (5) postID parameter in posts.aspx, (6)…
ModificadaAlta (7.5)2.7%💥 ExploitScriptdevelopers.net Netclassifieds3/12/200516/6/2026
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c)…
ModificadaMedia (5)3.5%💥 ExploitPhpalbum.net Phpalbum1/12/200516/6/2026
Directory traversal vulnerability in main.php in PHPAlbum 0.2.3 and earlier allows remote attackers to read arbitrary files via the (1) cmd and (2) var1 parameters.
ModificadaAlta (7.5)64%💥 ExploitATI Catalyst DriverMicrosoft .net FrameworkMicrosoft OfficeMicrosoft Project+219/8/200516/6/2026
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the…
ModificadaMedia (4.3)1.3%—Php.warpedweb.net Phppageprotect20/7/200516/6/2026
Vulnerabilidad de secuencia de comandos en sitios cruzados en PHPPageProtect 1.0.0a permite que atacantes remotos inyecten script web arbitrario o HTML mediante el parámetro "username" en "admin.php" o "login.php".
ModificadaMedia (5)18%—Microsoft Asp.net12/7/200516/6/2026
aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.
ModificadaMedia (5)1.0%—Frozenplague.net Plague News System6/7/200516/6/2026
SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (4.3)0.94%—Frozenplague.net Plague News System6/7/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.
ModificadaMedia (5)1.1%—Frozenplague.net Plague News System6/7/200516/6/2026
delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.
ModificadaMedia (5)40%—Microsoft Asp.net18/5/200516/6/2026
The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup.
ModificadaMedia (6.4)19%—Microsoft Asp.net18/5/200516/6/2026
The __VIEWSTATE functionality in Microsoft ASP.NET 1.x allows remote attackers to conduct replay attacks to (1) apply a ViewState generated from one view to a different view, (2) reuse ViewState information after the application's state has changed, or (3) use the ViewState to conduct attacks or expose content to…
ModificadaAlta (7.5)1.1%—Bugtracker.netAI2/5/200516/6/2026
Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (4.3)0.94%—YET Another Forum.net2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Yet Another Forum.net 0.9.9 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, or (3) Subject field.
ModificadaMedia (4.3)16%—Microsoft .net FrameworkMono14/3/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
ModificadaMedia (4.3)23%💥 ExploitMicrosoft Asp.net16/2/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
ModificadaMedia (4.3)1.8%💥 ExploitExpinion.net Member Management SystemAI31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Member Management System 2.1 allows remote attackers to inject arbitrary web script or HTML via (1) the err parameter to error.asp or (2) register.asp.
ModificadaMedia (4.3)0.94%—Minihttpserver.net Forum WEB Server31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Forum Web Server 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Subject field in post1.htm and (2) the File Description field in postfile2.htm.
ModificadaMedia (4.3)2.2%💥 ExploitExpinion.net News Manager Lite31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.
ModificadaMedia (4.6)0.31%—Minihttpserver.net WEB Forums ServerAI31/12/200416/6/2026
Web Forums Server 1.6 and 2.0 Power Pack stores passwords in plaintext in the Username.ini file, which allows local users to gain privileges.
ModificadaMedia (5)1.5%—Minihttpserver.net WEB Forums Server31/12/200416/6/2026
Directory traversal vulnerability in Web Forums Server 1.6 and 2.0 Power Pack allows remote attackers to read arbitrary files via a URL containing (1) "..\" (dot dot backslash), (2) "../" (dot dot slash), (3) "/%2E%2E%5C" (encoded dot dot backslash), or (4) "%2E%2E%2F" (encoded dot dot slash).
ModificadaCrítica (9.8)76%💥 ExploitMicrosoft Asp.net3/11/200416/6/2026
La característica de autenticación en formularios .NET permite a atacantes remotos evitar la autenticación de ficheros .aspx en directorios restringidos mediante una petición conteniendo un (1) 1) "" (barra invertida) or (2) ""%5C"" (barra invertida codificada).