Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 3.3% | — | Adobe Consulting Services Commons | 2/2/2021 | 17/6/2026 | ACS Commons version 4.9.2 (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in version-compare and page-compare due to invalid JCR characters that are not handled correctly. An attacker could potentially exploit this vulnerability to inject malicious JavaScript content into vulnerable… | |
| Modificada | Alta (7.5) | 1.2% | — | Nconsulting Nc-cms | 11/2/2019 | 17/6/2026 | lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata parameters. | |
| Modificada | Crítica (9.8) | 2.1% | — | Nconsulting Nc-cms | 31/10/2018 | 17/6/2026 | nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI. | |
| Modificada | Media (6.1) | 0.80% | — | Nconsulting Nc-cms | 15/10/2018 | 17/6/2026 | An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and containing a crafted SRC attribute of an IMG element. | |
| Modificada | Media (4.8) | 0.62% | — | Nconsulting Nc-cms | 14/10/2018 | 17/6/2026 | An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the form requires administrator privileges, and entering JavaScript is supported functionality | |
| Modificada | Crítica (9.8) | 3.5% | — | Brookinsconsulting Collected Information Export | 27/4/2018 | 17/6/2026 | Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data. | |
| Modificada | Media (5) | 1.3% | — | Longwaveconsulting Ubercart Securetrading Payment Method Module | 31/10/2012 | 16/6/2026 | The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.94% | — | Tag1consulting Support Timer | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Support Timer module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "track time spent" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 1.0% | — | Tag1consulting Support | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.87% | — | Hashmarkconsulting Controlpanel | 25/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Boesch It-consulting Progsys | 27/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Boesch It-consulting Simpnews | 26/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Boesch It-consulting Progsys | 23/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter. | |
| Modificada | Media (5) | 2.2% | — | Tamarack Consulting Tamarack Mmsd | 29/7/2006 | 16/6/2026 | Tamarack MMSd before 7.992 allows remote attackers to cause a denial of service (crash) via malformed RFC1006 (OSI over TCP/IP) packets. | |
| Modificada | Alta (10) | 3.6% | — | Himpfen Consulting PHP Simplenews | 19/3/2006 | 16/6/2026 | admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Curtis Specialty Consulting Iispop | 31/12/2002 | 16/6/2026 | Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110). | |
| Modificada | Alta (7.5) | 4.6% | — | Peaceworks Computer Consulting Phormation | 2/10/2001 | 16/6/2026 | Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Hassan Consulting Shopping Cart | 8/9/2001 | 16/6/2026 | shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Hassan Consulting Shopping Cart | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Baron Consulting Group Websitetool | 1/2/2000 | 16/6/2026 | The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. |