Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
869 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 3.2% | — | SUN Java Enterprise SystemSUN Java System Directory Server | 21/6/2006 | 16/6/2026 | Fallo de memoria en la Red de Servicios de Seguridad (NSS) 3.11, tal como se utiliza en Sun Java Enterprise System 2003Q4 2005Q1 y por medio de Java System Directory Server 5.2, permite a atacantes remotos causar una denegación de servicio (consumo de memoria) mediante la realización de un gran número de operaciones… | |
| Modificada | Media (4.3) | 1.2% | — | Alstrasoft Webhost Directory | 26/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, might allow remote attackers to inject arbitrary web script or HTML via the "write a review" box. NOTE: since user reviews do not require administrator privileges, and an auto-approve mechanism… | |
| Modificada | Media (5) | 1.7% | — | Alstrasoft Webhost Directory | 26/5/2006 | 16/6/2026 | (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error. NOTE: this issue might be resultant from SQL injection. | |
| Modificada | Alta (7.5) | 1.4% | — | Alstrasoft Webhost Directory | 26/5/2006 | 16/6/2026 | SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter. | |
| Modificada | Media (5.1) | 1.3% | — | Esyndicat Directory | 24/5/2006 | 16/6/2026 | admin/cron.php in eSyndicat Directory 1.2, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include arbitrary files and possibly execute arbitrary PHP code via a null-terminated value in the path_to_config parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Accomplishtechnology Phpmydirectory | 22/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | SUN Java System Directory Server | 22/5/2006 | 16/6/2026 | Unspecified vulnerability in the installation process in Sun Java System Directory Server 5.2 causes wrong user data to be written to a file created by the installation, which allows remote attackers or local users to gain privileges. | |
| Modificada | Alta (10) | 9.2% | — | Novell EdirectoryNovell Imonitor | 20/5/2006 | 16/6/2026 | Buffer overflow in iMonitor 2.4 in Novell eDirectory 8.8 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.2% | — | PHP Directory Listing Script | 16/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Directory Listing Script allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | Keyvan1.com Edirectorypro | 10/5/2006 | 16/6/2026 | SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5) | 2.1% | — | Annuaire Directory | 3/4/2006 | 16/6/2026 | Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path. | |
| Modificada | Media (6.8) | 1.3% | — | Annuaire Directory | 3/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inscription.php in Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary web script or HTML via the Comment Field (COMMENTAIRE parameter). | |
| Modificada | Alta (7.5) | 1.8% | — | Articlesone 99articles Directory | 22/3/2006 | 16/6/2026 | PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Boonex Barracuda Directory | 22/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest Category module. NOTE: the provenance of this information is unknown; portions of the details are obtained from third… | |
| Modificada | Media (5) | 9.7% | 💥 Exploit | IBM Tivoli Directory Server | 15/2/2006 | 16/6/2026 | IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite. | |
| Modificada | Media (5) | 9.9% | 💥 Exploit | SUN Java System Directory Server | 13/2/2006 | 16/6/2026 | LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite. | |
| Modificada | Alta (7.5) | 2.0% | — | Pdfdirectory | 19/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php,… | |
| Modificada | Alta (7.5) | 1.1% | — | Pdfdirectory | 19/1/2006 | 16/6/2026 | PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities. | |
| Modificada | Media (5) | 1.6% | — | IDV Directory Viewer | 5/1/2006 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en index.php en IDV Directory Viewer anteriores a 2005.1 permite a atacantes remotos ver el contenido de directorios de su elección mediante un .. (punto punto) en el parámetro "dir". | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (4.3) | 1.2% | — | MR. CGI GUY Amazon Search Directory | 6/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly the search parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 3/12/2005 | 16/6/2026 | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote… | |
| Analizada | Alta (7.5) | 4.1% | 💥 Exploit | Softbizscripts WEB Hosting Directory Script | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an… | |
| Modificada | Media (5.8) | 0.92% | — | IBM Tivoli Directory Server | 16/11/2005 | 16/6/2026 | slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Chipmunk Scripts Chipmunk Directory | 6/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter. |