Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Phpbb Ajax Shoutbox | 17/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (5.1) | 3.4% | 💥 Exploit | Knusperleicht Shoutbox | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter. | |
| Modificada | Media (5) | 4.0% | — | Nullsoft Shoutcast DSP | 12/7/2006 | 16/6/2026 | Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.7 allows remote attackers to read arbitrary files via unspecified vectors that are a "slight variation" of CVE-2006-3534. | |
| Modificada | Alta (7.8) | 2.5% | — | Nullsoft Shoutcast Server | 12/7/2006 | 16/6/2026 | Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote attackers to read arbitrary files via encoded dot dot (%2E%2E) sequences in an HTTP GET request for a file path containing "/content". | |
| Modificada | Media (4.3) | 2.0% | — | Nullsoft Shoutcast Server | 13/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Description, (2) URL, (3) Genre, (4) AIM, and (5) ICQ. | |
| Modificada | Baja (2.6) | 1.2% | — | Cynical Games Shoutbook | 19/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Baja (2.6) | 1.3% | — | Cynical Games Shoutbook | 19/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) NAME and (2) COMMENTS parameters. | |
| Modificada | Media (5) | 1.1% | 💥 Exploit | D2-shoutbox | 10/3/2006 | 16/6/2026 | SQL injection vulnerability in D2-Shoutbox 4.2 allows remote attackers to execute arbitrary SQL commands via the load parameter, when performing a Shoutbox action through Invision Power Board (IPB). | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Cynical Games Shoutlive | 1/3/2006 | 16/6/2026 | Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php. | |
| Modificada | Media (4.3) | 1.4% | — | Cynical Games Shoutlive | 1/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages. | |
| Modificada | Media (4.3) | 1.3% | — | Unknown Domain Shoutbox | 8/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Unknown Domain Shoutbox 2005.07.21 allow remote attackers to inject arbitrary web script or HTML, possibly via the (1) Handle or (2) Message fields. | |
| Modificada | Alta (7.5) | 1.2% | — | Unknown Domain Shoutbox | 8/2/2006 | 16/6/2026 | SQL injection vulnerability in Unknown Domain Shoutbox 2005.07.21 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |
| Modificada | Media (5) | 1.4% | — | Kshout | 3/8/2005 | 16/6/2026 | Kshout 2.x and 3.x stores settings.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords. | |
| Modificada | Alta (7.5) | 1.5% | — | Tkais Shoutbox | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in shoutact.php for TKai's Shoutbox allows remote attackers to execute arbitrary PHP code via the query parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Knusperleicht Shoutbox Script | 2/5/2005 | 16/6/2026 | Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to obtain sensitive information via a direct request to db/settings.dat, which displays usernames and password hashes. | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Nullsoft Shoutcast Server | 23/12/2004 | 16/6/2026 | Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file. | |
| Modificada | Baja (2.1) | 1.2% | 💥 Exploit | Nullsoft Shoutcast Server | 31/12/2003 | 16/6/2026 | Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL. | |
| Modificada | Baja (2.1) | 0.48% | — | Nullsoft Shoutcast Server | 22/4/2003 | 16/6/2026 | SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file. | |
| Modificada | Media (5) | 6.6% | 💥 Exploit | Endity.com Shoutbox | 11/4/2003 | 16/6/2026 | Cross-site scripting vulnerability in board.php of endity.com ShoutBOX allows remote attackers to inject arbitrary HTML into the shoutbox page via the site parameter. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Nullsoft Shoutcast Server | 4/10/2002 | 16/6/2026 | Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-". | |
| Modificada | Alta (7.5) | 3.3% | — | Analogx Simpleserver Shout | 4/10/2002 | 16/6/2026 | Buffer overflow in AnalogX SimpleServer:Shout 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long request to TCP port 8001. | |
| Modificada | Alta (7.5) | 3.4% | — | Nullsoft Shoutcast Server | 16/5/2002 | 16/6/2026 | Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes. | |
| Modificada | Media (5) | 1.9% | — | Nullsoft Shoutcast Server | 3/8/2001 | 16/6/2026 | Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header. | |
| Modificada | Alta (10) | 3.1% | — | Shoutcast Dnas | 26/3/2001 | 16/6/2026 | Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description. | |
| Modificada | Alta (7.5) | 3.3% | — | IcecastLibshout | 12/3/2001 | 16/6/2026 | Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. |