Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 3.6% | 💥 Exploit | Betaparticle Blog | 21/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in BetaParticle Blog 6.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp or (2) fldGalleryID parameter to template_gallery_detail.asp. | |
| Modificada | Media (6.4) | 1.5% | — | Ecartis | 21/1/2006 | 16/6/2026 | Pantomime en Ecartis 1.0.0 snapshot 20050909 almacena los archivos adjuntos de correo electrónico en un directorio accesible al público, lo que puede permitir a atacantes remotos subir archivos arbitrarios. | |
| Modificada | Media (5.1) | 1.7% | — | Martin Bauer Gbook | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header field. | |
| Modificada | Alta (7.5) | 1.2% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 3/12/2005 | 16/6/2026 | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpwordpress PHP News AND Article Manager | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action. | |
| Modificada | Alta (7.5) | 1.2% | — | Interspire Articlelive NX | 21/11/2005 | 16/6/2026 | SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Interspire Articlelive | 11/5/2005 | 16/6/2026 | ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie. | |
| Modificada | Media (4.3) | 1.4% | — | Interspire Articlelive | 11/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5) BlogId parameter. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Betaparticle Blog | 2/5/2005 | 16/6/2026 | betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that vector 2 also affects versions 6.0 through 9.0. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Betaparticle Blog | 2/5/2005 | 16/6/2026 | betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Interspire Articlelive | 23/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Outstart Participate Enterprise | 8/3/2005 | 16/6/2026 | Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete… | |
| Modificada | Media (4.3) | 1.3% | — | Martin Bauer Gbook | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in GBook for PHP-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via cookies that are stored in the $_COOKIE PHP variable, which is not cleansed by PHP-Nuke. | |
| Modificada | Media (4.3) | 1.3% | — | Martin Bauer Gbook | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in GBook for Php-Nuke 1.0 allows remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) name, (2) email, (3) city, and (4) message, which do not use the <script> and <style> tags, which are filtered by PHP-Nuke. | |
| Modificada | Media (4.6) | 0.36% | — | Ecartis | 31/12/2004 | 16/6/2026 | Unknown vulnerability in ecartis 0.x before 0.129a+1.0.0-snap20020514-1.3 and 1.x before 1.0.0+cvs.20030911-8 allows attackers in the same domain to gain administrator privileges and modify configuration. | |
| Modificada | Alta (7.5) | 1.2% | — | DWC ArticlesAI | 23/10/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements. | |
| Modificada | Alta (10) | 2.8% | — | Ecartis | 4/5/2004 | 16/6/2026 | Mültiples desbordamientos de búfer en ecartis anteriores a 1.0.0 permite a atacantes causar una denegación de servicio y posiblemente ejecutar código arbitrario. | |
| Modificada | Alta (10) | 1.4% | — | Ecartis | 4/5/2004 | 16/6/2026 | Vulnerabilidad desconocida en ecartis anteriores a 1.0.0 no validad adecuadamente datos introducidos por el usuario, lo que permite a atacantes obtener contraseñas de listas de correo. | |
| Modificada | Alta (7.5) | 1.6% | — | Ecartis | 2/4/2003 | 16/6/2026 | Ecartis 1.0.0 (formerly listar) before snapshot 20030227 allows remote attackers to reset passwords of other users and gain privileges by modifying hidden form fields in the HTML page. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Martin Bauer Gbook | 31/3/2003 | 16/6/2026 | index.php in gBook 1.4 allows remote attackers to bypass authentication and gain administrative privileges by setting the login parameter to true. | |
| Modificada | Media (4.6) | 0.80% | 💥 Exploit | EcartisListar | 12/8/2002 | 16/6/2026 | Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or… | |
| Modificada | Alta (10) | 6.2% | — | EcartisListar | 12/8/2002 | 16/6/2026 | Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c. | |
| Modificada | Alta (7.2) | 0.46% | — | EcartisListar | 12/8/2002 | 16/6/2026 | Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA's, which could allow local users to gain privileges. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Martin Roesch Snort | 25/3/2002 | 16/6/2026 | El snort 1.8.3 no define correctamente el tamaño mínimo de cabecera ICMP, que permite a atacantes remotos causar una negación de servicio (crash y core dump) vía un paquete mal formado ICMP. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Martin Hamilton Roads | 2/6/2001 | 16/6/2026 | ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form parameter and terminating the filename with a null byte. |