Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.1% | — | Collectivecolors Taxonomy View Integrator Module | 19/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Taxonomy Views Integrator (TVI) module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to "views pages." | |
| Modificada | Media (6.9) | 0.97% | — | Adobe Livecycle Designer | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Adobe LiveCycle Designer 8.2.1.3144.1.471865 allows local users to gain privileges via a Trojan horse .dll file in the current working directory, as demonstrated by a directory that contains a .tds file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.9) | 0.82% | — | Adobe Livecycle Designer ES2 | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Adobe LiveCycle Designer ES2 9.0.0.20091029.1.612548 allows local users to gain privileges via a Trojan horse objectassisten_US.dll file in the current working directory, as demonstrated by a directory that contains a .tds file. NOTE: the provenance of this information is… | |
| Modificada | Baja (2.1) | 1.1% | — | Creative Commons Module Project Creativecommons | 26/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote authenticated users with the administer creative commons permission to inject arbitrary web script or HTML via the (1) creativecommons_user_message or (2)… | |
| Modificada | Media (5) | 3.8% | — | Adobe BlazedsAdobe Livecycle Data ServicesAdobe Livecycle | 16/6/2011 | 16/6/2026 | Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly handle object graphs, which allows attackers to cause a denial of service via unspecified vectors, related to a "complex object graph vulnerability." | |
| Modificada | Alta (10) | 6.1% | — | Adobe BlazedsAdobe Livecycle Data ServicesAdobe Livecycle | 16/6/2011 | 16/6/2026 | Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization… | |
| Modificada | Alta (7.2) | 0.97% | 💥 Exploit | Securstar Drivecrypt | 20/1/2011 | 16/6/2026 | DCR.sys driver in SecurStar DriveCrypt 5.4, 5.3, and earlier allows local users to execute arbitrary code via a crafted argument to the 0x00073800 IOCTL. | |
| Modificada | Media (6) | 1.5% | — | Activecollab | 7/1/2011 | 16/6/2026 | ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to an object, via a crafted URL. | |
| Modificada | Media (4.3) | 1.3% | — | Tibco ActivecatalogTibco Collaborative Information Manager | 7/1/2011 | 16/6/2026 | Session fixation vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to hijack web sessions via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Tibco ActivecatalogTibco Collaborative Information Manager | 7/1/2011 | 16/6/2026 | Unspecified vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to modify data or obtain sensitive information via a crafted URL. | |
| Modificada | Media (4.3) | 1.3% | — | Tibco ActivecatalogTibco Collaborative Information Manager | 7/1/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Tibco ActivecatalogTibco Collaborative Information Manager | 7/1/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Collaborative Information Manager server, as used in TIBCO Collaborative Information Manager before 8.1.0 and ActiveCatalog before 1.0.1, allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Analizada | Media (6.5) | 90% | ⚠ Explotación activa💥 Exploit | Adobe BlazedsAdobe ColdfusionAdobe Flex Data ServicesAdobe Livecycle+1 | 15/2/2010 | 6/8/2026 | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request,… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joompolitan COM Livechat | 30/7/2009 | 16/6/2026 | SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Joompolitan COM Livechat | 30/7/2009 | 16/6/2026 | Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joompolitan COM Livechat | 30/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php. | |
| Modificada | Media (4.3) | 1.0% | — | Activecollab | 12/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in A51 D.O.O. activeCollab 0.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1772. | |
| Modificada | Media (5) | 1.9% | — | Activecollab | 22/5/2009 | 16/6/2026 | activeCollab 2.1 Corporate allows remote attackers to obtain sensitive information via an invalid re_route parameter to the login script, which reveals the installation path in an error message. | |
| Modificada | Media (4.3) | 1.6% | — | Activecollab | 22/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web script or HTML via the re_route parameter to the login script. | |
| Modificada | Media (4.3) | 1.1% | — | Activecampaign Triolive | 13/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Activecampaign Triolive | 13/11/2008 | 16/6/2026 | SQL injection vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to execute arbitrary SQL commands via the department_id parameter to index.php. | |
| Modificada | Baja (2.1) | 0.35% | — | Secustar Drivecrypt Plus Pack | 3/9/2008 | 16/6/2026 | Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Livecart | 11/4/2008 | 16/6/2026 | SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to the /category URI. | |
| Modificada | Media (4.3) | 4.1% | — | Adobe Livecycle Workflow | 12/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web management interface in Adobe LiveCycle Workflow 6.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Integry Systems Livecart | 4/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LiveCart 1.0.1, and possibly other versions before 1.1.0, allow remote attackers to inject arbitrary web script or HTML via (1) the return parameter to user/remindPassword, (2) the q parameter to the category script, (3) the return parameter to the order script,… |