Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 12% | 💥 Exploit | Freewebshop | 10/11/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2006-5773. | |
| Modificada | Media (6.1) | 2.0% | 💥 Exploit | Freewebshop | 10/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Freewebshop | 6/11/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in FreeWebshop 2.2.1 and earlier allows remote attackers to read arbitrary files and disclose the installation path via a .. (dot dot) in the action parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Freewebshop | 6/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) prod parameter. | |
| Modificada | Media (5.1) | 2.6% | 💥 Exploit | Cardway Digitalwebshop | 23/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _PHPLIB[libdir] parameter to (1) rechnung.php or (2) prepend.php. | |
| Modificada | Media (4.3) | 1.2% | — | Apt-webshop-system | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to inject arbitrary web script or HTML via the message parameter, probably involving the basket functionality. | |
| Modificada | Media (5) | 1.2% | — | Apt-webshop-system | 11/4/2006 | 16/6/2026 | Unspecified vulnerability in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allows remote attackers to access unspecified files via a modified warp parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Apt-webshop-system | 11/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in modules.php in APT-webshop-system 4.0 PRO, 3.0 BASIC, and 3.0 LIGHT allow remote attackers to execute arbitrary SQL commands via the (1) group, (2) seite, and (3) id parameter, possibly involving the artikel functionality. NOTE: this vulnerability also allows resultant path… | |
| Modificada | Alta (10) | 6.1% | — | Mcafee Webshield Smtp | 4/4/2006 | 16/6/2026 | Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed. | |
| Modificada | Media (4.6) | 0.40% | — | Twofold Photos Webshots Desktop | 31/12/2002 | 16/6/2026 | Webshots Desktop screensaver allows local users to bypass the password on the screensaver by pressing CTRL-ALT-DELETE and (1) hitting the cancel button or (2) killing the screensaver from the task manager. | |
| Modificada | Alta (7.5) | 6.7% | — | GFI MailsecurityNetwork Associates Webshield SmtpRoaring Penguin CanitRoaring Penguin Mimedefang+1 | 24/9/2002 | 16/6/2026 | SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly")… | |
| Modificada | Media (5) | 13% | 💥 Exploit | Bbshareware.com Phusion Webserver | 31/5/2002 | 16/6/2026 | Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request. | |
| Modificada | Media (5) | 8.8% | 💥 Exploit | Bbshareware.com Phusion Webserver | 31/5/2002 | 16/6/2026 | Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request. | |
| Modificada | Alta (7.5) | 2.8% | — | Network Associates Webshield Smtp | 31/12/2001 | 16/6/2026 | NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments. | |
| Modificada | Alta (7.5) | 5.7% | — | Mcafee Webshield SmtpNetwork Associates Gauntlet FirewallPGP E-ppliance 300SGI Irix+1 | 4/9/2001 | 16/6/2026 | Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message. | |
| Modificada | Alta (7.5) | 3.3% | — | IcecastLibshout | 12/3/2001 | 16/6/2026 | Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.5% | — | Network Associates Webshield Smtp | 9/1/2001 | 16/6/2026 | McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Network Associates Webshield Smtp | 9/1/2001 | 16/6/2026 | McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field. | |
| Modificada | Media (5) | 1.7% | — | Network Associates Webshield Smtp | 20/10/2000 | 16/6/2026 | WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail. | |
| Modificada | Alta (10) | 5.9% | 💥 Exploit | Network Associates Gauntlet FirewallNetwork Associates WebshieldNetwork Associates Webshield E-ppliance | 18/5/2000 | 16/6/2026 | Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands. | |
| Modificada | Alta (7.5) | 3.5% | — | Network Associates Webshield | 1/5/2000 | 16/6/2026 | Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service. | |
| Modificada | Media (5) | 2.4% | — | Network Associates Webshield | 1/5/2000 | 16/6/2026 | The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command. |