Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 5.7% | 💥 Exploit | Phpbb Searchindexer | 20/10/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en archive/archive_topic.php en pbpbb para los motores de búsqueda (SearchIndexer) (también conocido como phpBBSEI) para phpBB permite a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro phpbb_root_path. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Darrens 5-dollar Script Archive Flashchat | 6/9/2006 | 16/6/2026 | Múltiples vulnerabilidades PHP de inclusión remota de archivo en FlashChat anterior a 4.6.2 permite a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro dir[inc] en (1) inc/cmses/aedatingCMS, (2) inc/cmses/aedatingCMS2.php, o (3) inc/cmses/aedating4CMS.php. | |
| Modificada | Alta (9.3) | 4.6% | — | Conexware Powerarchiver | 5/8/2006 | 16/6/2026 | Desbordamiento de búfer basado en pila en ZIPS32.DLL 6.0.0.4 en ConeXware PowerArchiver 9.62.03 permite a atacantes con la intervención del usuario ejecutar código de su elección añadiendo un nuevo archivo a un archivo ZIP manipulado que contiene un archivo con un largo nombre. | |
| Modificada | Media (5) | 1.2% | — | Darrens 5-dollar Script Archive Osdate | 21/7/2006 | 16/6/2026 | Darren's $5 Script Archive osDate 1.1.7 y anteriores permite a usuarios aumentar ilícitamente sus propias calificaciones mediante un parámetro txtrating con una puntuación mayor que el máximo pretendido de 10. | |
| Modificada | Media (6.8) | 1.7% | — | Darrens 5-dollar Script Archive Osdate | 21/7/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en showprofile.php de Darren's $5 Script Archive osDate 1.1.7 y versiones anteriores permite a atacantes remotos inyectar scripts web o HTML de su elección mediante el atributo onerror en una etiqueta HTML IMG con un fichero fuente no existente en el… | |
| Modificada | Media (4.3) | 1.4% | — | Emailarchitect Email Server | 21/6/2006 | 16/6/2026 | Vulnerabilidad cross-site scripting (XSS) en Servidor de correo electrónico Emailarchitect v6.1 permite a atacantes remotos la ejecución de JavaScript arbitrario a través de una etiqueta div HTML con un retorno de carro entre el atributo onmouseover y su valor, que no pasa por el filtro de correo. | |
| Modificada | Baja (2.6) | 1.3% | — | Anton Belev MP3 Search Archive | 19/6/2006 | 16/6/2026 | Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en index.php en MP3 Search/Archive v1.2 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetro (1) keywords, tal y como se usa en el "cuadro de búsqueda", y (2) el parámetro res. | |
| Modificada | Baja (2.6) | 1.9% | — | Emailarchitect Email Server | 12/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 6.1.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) errCode and (2) uid parameter in (a) default.asp and (3) dname parameter in (b) /admin/dns.asp and (c) /additional/regdomain_done.asp. | |
| Modificada | Media (4.3) | 1.2% | — | Community Architect Guestbook | 25/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed by fsguestbook.html. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (5) | 1.6% | — | KGB Archiver | 4/4/2006 | 16/6/2026 | Directory traversal vulnerability in KGB Archiver before 1.1.5.22 allows remote attackers to overwrite arbitrary files wile decompressing an archive, possibly due to directory traversal sequences in a filename. | |
| Modificada | Media (5) | 2.4% | — | Pear Archive TAR | 28/2/2006 | 16/6/2026 | Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive. | |
| Modificada | Media (5) | 1.9% | — | Pear Archive ZIP | 28/2/2006 | 16/6/2026 | Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive. | |
| Modificada | Media (4.6) | 0.59% | — | Autodesk 3DS MAXAutodesk Architectural DesktopAutodesk AutocadAutodesk Autocad Civil 3D+14 | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Quicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise | 20/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters. | |
| Modificada | Media (4.3) | 1.2% | — | Quicksquare Development Honeycomb Archive Enterprise | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm. | |
| Modificada | Alta (7.5) | 1.5% | — | Archilles Newsworld | 2/11/2005 | 16/6/2026 | Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd and (2) session.nwd under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames, hashed passwords, and session IDs, and gain privileges. | |
| Modificada | Crítica (9.8) | 2.3% | — | Archilles Newsworld | 2/11/2005 | 16/6/2026 | admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument. | |
| Modificada | Alta (7.5) | 3.2% | — | Powerarchiver 2002Powerarchiver 2003Powerarchiver 2004Powerarchiver 2006 | 27/9/2005 | 16/6/2026 | Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive. | |
| Modificada | Media (6.4) | 1.7% | — | Csystems Webarchivex | 14/9/2005 | 16/6/2026 | WebArchiveX.dll 5.5.0.76 installed before September 6th, 2005 is marked safe for scripting by default, which allows remote attackers to read or write to arbitrary files via the (1) MakeArchive or (2) MakeArchiveStr methods. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 9/2/2005 | 16/6/2026 | Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target… |