Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | 💥 Exploit | Isolsoft Support Center | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Supportpro Supportdesk | 26/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SupportPRO Supportdesk allows remote attackers to inject arbitrary web script or HTML via the (1) post tickers and (2) view tickets options. | |
| Modificada | Media (5) | 1.6% | — | Activecampaign SupporttrioAI | 26/11/2005 | 16/6/2026 | index.php in ActiveCampaign SupportTrio 1.4 and earlier allows remote attackers to read or include arbitrary files via the page parameter, possibly due to a directory traversal vulnerability. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | Kayako Esupport | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Kayako Esupport | 30/3/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en index.php para Kayako ESupport 2.3.1 y posiblemete otras versiones, permite a atacantes remotos la inyección de HTML arbitrario y scripts web, mediante el parámetro nav. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Netsupport DNA Helpdesk | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Kayako Esupport | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary web script or HTML via the searchm parameter. | |
| Modificada | Media (5) | 1.1% | 💥 Exploit | Kayako Esupport | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands via the (1) subcat, (2) rate, (3) questiondetails, (4) ticketkey22, (5) email22 parameters to index.php, or (6) the e-mail field of the Forgot Key feature. | |
| Modificada | Media (4.6) | 0.81% | 💥 Exploit | Netsupport School | 25/3/2004 | 16/6/2026 | Invision NetSupport School Pro uses a weak encryption algorithm to encrypt passwords, which allows local users to obtain passwords. | |
| Modificada | Media (4.4) | 0.28% | — | Ncipher Support Software | 31/12/2003 | 16/6/2026 | nCipher Support Software 6.00, when using generatekey KeySafe to import keys, does not delete the temporary copies of the key, which may allow local users to gain access to the key by reading the (1) key.pem or (2) key.der files. | |
| Modificada | Media (4.6) | 0.32% | — | Debian Mime-support | 12/5/2003 | 16/6/2026 | run-mailcap en mime-support 3.22 y anteriores permite a usuarios locales sobreescribir ficheros arbitrarios mediante un ataque de enlaces simbólicos en ficheros temporales. | |
| Modificada | Media (5) | 7.8% | 💥 Exploit | Coxco Support A-cartCoxco Support MetacartCoxco Support Midicart ASPCoxco Support Midicart ASP Maxi+3 | 11/4/2003 | 16/6/2026 | MidiCart almacena el fichero de base de datos midicart.mdb bajo la raíz de documentos web, lo que permite a atacantes remotos robar información sensible pidiendo la base de datos directamente. | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | National Language Support Libim | 3/3/2003 | 16/6/2026 | Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users to gain privileges via several possible attack vectors, including a long -im argument to aixterm. | |
| Modificada | Media (5) | 1.6% | — | Sony Vaio Manual Cybersupport | 31/12/2002 | 16/6/2026 | Unknown vulnerability in the "VAIO Manual" software in certain Sony VAIO personal computers sold from November 2001 to January 2002, allows remote attackers to modify data via a web page or HTML e-mail. | |
| Modificada | Media (5) | 2.1% | — | Cgiscript.net Cslivesupport | 31/12/2002 | 16/6/2026 | csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. | |
| Modificada | Media (4.6) | 0.51% | — | HP Instant Support | 4/10/2002 | 16/6/2026 | Unknown vulnerability in HP Instant Support Enterprise Edition (ISEE) product U2512A for HP-UX 11.00 and 11.11 may allow authenticated users to access restricted files. | |
| Modificada | Media (5) | 2.1% | — | Newlog Netsupport Manager | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request. | |
| Modificada | Media (5) | 1.7% | — | IBM AIX Parallel Systems Support Programs | 1/4/2002 | 16/6/2026 | Unknown vulnerability in IBM AIX Parallel Systems Support Programs (PSSP) 3.1.1, 3.2, and 3.4 allows remote attackers to read arbitrary files from a file collection. | |
| Modificada | Baja (2.1) | 0.52% | — | HP Support Tools Manager | 12/2/2001 | 16/6/2026 | Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file. |