Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
746 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 1.7% | — | Cisco ASA 5500Cisco VPN 3000 Concentrator Series Software | 19/6/2006 | 16/6/2026 | Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en WebVPN en la serie Cisco VPN 3000 y concentradores Cisco ASA 5500 Series Adaptive Security Appliances (ASA), cuando se encuentra en el modo de WebVPN sin cliente, permite a atacantes remotos inyectar secuencias de comandos web o HTML a… | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Ubbcentral Ubb.threads | 2/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords. | |
| Modificada | Alta (7.6) | 7.3% | 💥 Exploit | Zipcentral | 1/6/2006 | 16/6/2026 | Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename. | |
| Modificada | Media (5.1) | 2.5% | 💥 Exploit | Ubbcentral Ubb.threads | 30/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters. | |
| Modificada | Media (5.1) | 7.9% | 💥 Exploit | Ubbcentral Ubb.threads | 24/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter. | |
| Modificada | Media (5) | 0.96% | — | Ubbcentral Ubb.threads | 28/3/2006 | 16/6/2026 | SQL injection vulnerability in showflat.php in UBB.threads 5.5.1, 6.0 br5, 6.0.1, 6.0.2, and earlier, allows remote attackers to execute arbitrary SQL commands via the Number parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Ubbcentral Ubb.threads | 4/2/2006 | 16/6/2026 | SQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the Number parameter. | |
| Modificada | Alta (7.8) | 3.2% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3030 Concentator | 31/1/2006 | 16/6/2026 | Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet. | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+17 | 22/12/2005 | 16/6/2026 | The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the… | |
| Modificada | Media (5) | 5.2% | — | Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+4 | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details… | |
| Modificada | Alta (7.5) | 5.6% | — | Symantec Veritas Storage ExecSymantec Veritas Storagecentral | 20/9/2005 | 16/6/2026 | Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls. | |
| Modificada | Media (5) | 1.3% | — | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter. | |
| Modificada | Media (6.5) | 0.96% | — | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to… | |
| Modificada | Media (6.8) | 1.5% | — | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to… | |
| Modificada | Media (5) | 1.3% | — | Ubbcentral Ubb.threads | 29/6/2005 | 16/6/2026 | Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte. | |
| Modificada | Media (5) | 2.3% | — | Cisco VPN 3000 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+4 | 20/6/2005 | 16/6/2026 | Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname. | |
| Modificada | Media (4.3) | 0.94% | — | Centra | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields. | |
| Modificada | Alta (7.5) | 1.2% | — | Ubbcentral Ubb.threads | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter. | |
| Modificada | Media (5) | 1.6% | — | Cisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 Concentrator+4 | 30/3/2005 | 16/6/2026 | Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Ubbcentral Ubb.threads | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Ubbcentral Ubb.threads | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to inject arbitrary web script or HTML via the Cat parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Ubbcentral Ubb.threads | 21/10/2004 | 16/6/2026 | SQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter. | |
| Modificada | Alta (7.2) | 1.5% | — | Cluecentral Suexec.patch | 6/8/2004 | 16/6/2026 | El programa modificado suexec de cPanel, cuando se configura para mod_php y compila para Apache 1.3.31 y anteriores sin mod_phpsuexec, permite a usuarios locales ejecutar scripts compartidos que no son de confianza y ganar privilegios, como se ha demostrado usando scripts como (1)proftpdvhosts or (2) addalink.cgi, una… | |
| Modificada | Media (5) | 2.1% | — | Cisco VPN 3015 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 ConcentratorCisco VPN 3080 Concentrator+2 | 27/5/2003 | 16/6/2026 | Concentradores de Cisco de la serie VPN 3000 y Cisco VPN 3002 Hardware Client 2.x.x hasta 3.6.7A permiten que atacantes remotos causen una denegación de servicio (ralentización y posiblemente recarga) mediante una inundación con paquetes ICMP mal construídos. |