Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Cgiscript.net Csfaq | 6/8/2004 | 16/6/2026 | csFAQ.cgi in csFAQ allows remote attackers to gain sensitive information via an invalid database parameter, which reveals the path to the web server in an error message. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | BEA Weblogic ServerBorland Software J BuilderBusinessobjects Crystal EnterpriseBusinessobjects Crystal Enterprise Java SDK+5 | 6/8/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en los visores web de Business Objects Crystal Reports 9 and 10, y Crystal Enterprise 9 o 10, usados en Visual Studio .NET 2003 y Outlook 2003 con Business Contact Manager, Microsoft Business Solutions CRM 1.2, y otros productos, permiten a atacantes remotos leer y… | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Expinion.net News Manager Lite | 20/3/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Expinion.net News Manager LiteAI | 20/3/2004 | 16/6/2026 | News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Expinion.net Member Management SystemAI | 20/3/2004 | 16/6/2026 | SQL injection vulnerability in Member Management System 2.1 allows remote attackers to execute arbitrary SQL via the ID parameter to (1) resend.asp or (2) news_view.asp. | |
| Modificada | Alta (7.5) | 1.5% | — | Phpdig.net Phpdig | 17/2/2004 | 16/6/2026 | Vulnerabilidad de inclusión de código PHP remoto en config.php de PhpDig 1.6.5 y anteriores permite a atacantes remotos ejecutar código PHP arbitrario modificando el parámetro $relative_script_path para referenciar a una URL en servidor web remoto que contiene el código. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Amxmod.net AMX MOD | 31/12/2003 | 16/6/2026 | Format string vulnerability in AMX 0.9.2 and earlier, a plugin for Valve Software's Half-Life Server, allows remote attackers to execute arbitrary commands via format string specifiers in the amx_say command. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Attila-php.net Attilaphp | 20/10/2003 | 16/6/2026 | SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to bypass authentication via a modified cook_id parameter. | |
| Modificada | Media (6.8) | 13% | — | Microsoft Asp.net | 22/9/2003 | 16/6/2026 | Microsoft ASP.Net 1.1 permite a atacantes remotos saltarse la protección contra inyección de script y secuencias de comandos en sitios cruzados (XSS) mediante un carácter nulo al comienzo de un nombre de etiqueta. | |
| Modificada | Baja (3.6) | 0.32% | — | Aboleo.net Portmon | 24/7/2003 | 16/6/2026 | Portmon 1.7 y posiblemente versiones anteriores permiten a usuarios locales leer y escribir ficheros arbitrarios mediante las opciones de línea de comandos -c (fichero anfitrión) o -l (fichero de registro). | |
| Modificada | Media (6.4) | 7.4% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Vulnerabilidad de franqueo de directorios en Snowblind Web Server 1.0 permite que atacantes remotos lean ficheros arbitrarios mediante un ".." (punto punto) en una petición HTTP. | |
| Modificada | Media (6.4) | 5.9% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Snowblind Web Server 1.0 permite que atacantes remotos causen una denegación de servicio (caída) por medio de una URL que finaliza en una secuencia de "</". | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Snowblind Web Server 1.0 permite que atacantes remotos provoquen una denegación de servicio (caída) y posiblemente ejecuten código arbitrario mediante una petición HTTP larga, lo cual puede desencadenar un desbordamiento de búfer. | |
| Modificada | Media (6.4) | 2.2% | — | Snowblind.net Snowblind WEB Server | 16/6/2003 | 16/6/2026 | Vulnerabilidad de franqueo de directorios en Snowblind Web Server 1.0 permite que atacantes remotos listen contenidos de directorios arbitrarios mediante un ... (3 puntos) en una petición HTTP. | |
| Modificada | Media (5) | 2.1% | — | Cgiscript.net Cslivesupport | 31/12/2002 | 16/6/2026 | csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. | |
| Modificada | Media (5) | 16% | — | Microsoft .net Windows ServerMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows XP | 11/10/2002 | 16/6/2026 | The Remote Data Protocol (RDP) version 5.1 in Microsoft Windows XP allows remote attackers to cause a denial of service (crash) when Remote Desktop is enabled via a PDU Confirm Active data packet that does not set the Pattern BLT command, aka "Denial of Service in Remote Desktop." | |
| Modificada | Media (5) | 22% | — | Microsoft .net Windows ServerMicrosoft Windows 2000Microsoft Windows 2000 Terminal ServicesMicrosoft Windows NT+1 | 11/10/2002 | 16/6/2026 | Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol." | |
| Modificada | Alta (7.5) | 1.4% | — | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability. | |
| Modificada | Media (5.1) | 1.3% | — | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed. | |
| Modificada | Alta (7.5) | 2.4% | — | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page. | |
| Modificada | Media (5) | 1.3% | — | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other configuration settings, via the viewnews command with an invalid database, which leaks the information in error messages. |