Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)3.6%💥 ExploitBetaparticle Blog21/3/200616/6/2026
Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp.
ModificadaMedia (6.4)1.5%—Ecartis21/1/200616/6/2026
Pantomime en Ecartis 1.0.0 snapshot 20050909 almacena los archivos adjuntos de correo electrónico en un directorio accesible al público, lo que puede permitir a atacantes remotos subir archivos arbitrarios.
ModificadaMedia (5.1)1.7%—Martin Bauer Gbook31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header field.
ModificadaAlta (7.5)1.2%—Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+73/12/200516/6/2026
SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote…
ModificadaAlta (7.5)1.2%💥 ExploitPhpwordpress PHP News AND Article Manager26/11/200516/6/2026
SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.
ModificadaAlta (7.5)1.2%—Interspire Articlelive NX21/11/200516/6/2026
SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query parameter.
ModificadaAlta (7.5)1.9%—Interspire Articlelive11/5/200516/6/2026
ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.
ModificadaMedia (4.3)1.4%—Interspire Articlelive11/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5) BlogId parameter.
ModificadaMedia (5)3.5%💥 ExploitBetaparticle Blog2/5/200516/6/2026
betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0.
ModificadaAlta (7.5)3.5%💥 ExploitBetaparticle Blog2/5/200516/6/2026
betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.
ModificadaMedia (4.3)3.5%💥 ExploitInterspire Articlelive23/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter.
ModificadaAlta (7.5)1.5%—Outstart Participate Enterprise8/3/200516/6/2026
Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete…
ModificadaMedia (4.3)1.3%—Martin Bauer Gbook31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via cookies that are stored in the $_COOKIE PHP variable, which is not cleansed by PHP-Nuke.
ModificadaMedia (4.3)1.3%—Martin Bauer Gbook31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke.
ModificadaMedia (4.6)0.36%—Ecartis31/12/200416/6/2026
Unknown vulnerability in ecartis 0.x before 0.129a+1.0.0-snap20020514-1.3 and 1.x before 1.0.0+cvs.20030911-8 allows attackers in the same domain to gain administrator privileges and modify configuration.
ModificadaAlta (7.5)1.2%—DWC ArticlesAI23/10/200416/6/2026
Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements.
ModificadaAlta (10)2.8%—Ecartis4/5/200416/6/2026
Mültiples desbordamientos de búfer en ecartis anteriores a 1.0.0 permite a atacantes causar una denegación de servicio y posiblemente ejecutar código arbitrario.
ModificadaAlta (10)1.4%—Ecartis4/5/200416/6/2026
Vulnerabilidad desconocida en ecartis anteriores a 1.0.0 no validad adecuadamente datos introducidos por el usuario, lo que permite a atacantes obtener contraseñas de listas de correo.
ModificadaAlta (7.5)1.6%—Ecartis2/4/200316/6/2026
Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page.
ModificadaAlta (10)10%💥 ExploitMartin Bauer Gbook31/3/200316/6/2026
index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true.
ModificadaMedia (4.6)0.80%💥 ExploitEcartisListar12/8/200216/6/2026
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or…
ModificadaAlta (10)6.2%—EcartisListar12/8/200216/6/2026
Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c.
ModificadaAlta (7.2)0.46%—EcartisListar12/8/200216/6/2026
Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA's, which could allow local users to gain privileges.
ModificadaMedia (5)3.6%💥 ExploitMartin Roesch Snort25/3/200216/6/2026
El snort 1.8.3 no define correctamente el tamaño mínimo de cabecera ICMP, que permite a atacantes remotos causar una negación de servicio (crash y core dump) vía un paquete mal formado ICMP.
ModificadaMedia (5)7.5%💥 ExploitMartin Hamilton Roads2/6/200116/6/2026
ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte.
Orbitaley — Vulnerabilidades