Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 167 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
924 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Citrix MetaframeCitrix Metaframe Presentation ServerCitrix Presentation Server | 24/7/2006 | 16/6/2026 | Citrix MetaFrame para XP 1.0 característica 1, excepto cuando funciona sobre Windows Server 2003, instala una llave de registro con un ACL no seguro, lo cual permite a usuarios remotos validos ganar privilegios. | |
| Modificada | Alta (7.5) | 1.2% | — | Orbitcoders Orbitmatrix | 18/7/2006 | 16/6/2026 | index.php en Orbitcoders OrbitMATRIX 1.0 permite a atacantes remotos disparar un error SQL a través del parámetro page_name, posiblemente debido a una vulnerabilidad de inyección SQL. | |
| Modificada | Media (4.3) | 1.2% | — | Orbitcoders Orbitmatrix | 18/7/2006 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en index.php en Orbitcoders OrbitMATRIX 1.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro page_name con una etiqueta IMG que contiene una URI javascript en el atributo SRC. | |
| Modificada | Media (5) | 1.2% | — | Orbitcoders Orbitmatrix | 18/7/2006 | 16/6/2026 | index.php en Orbitcoders OrbitMATRIX 1.0 permite a atacantes remotos obtener información sensible (esquemas parciales de la base de datos) a través de parámetros page_name modificados, lo cual refleja porciones de una consulta SQL en el resultado. NOTA: no está clara si la información tiene un objetivo-especifico. Si… | |
| Modificada | Media (5) | 1.9% | — | Bitrix Site Manager | 19/5/2006 | 16/6/2026 | The Update functionality in Bitrix Site Manager 4.1.x does not verify the authenticity of downloaded updates, which allows remote attackers to obtain sensitive information and ultimately execute arbitrary PHP code via DNS cache poisoning that redirects the user to a malicious site. | |
| Modificada | Media (4.9) | 1.1% | — | Bitrix Site Manager | 19/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HTML via unspecified inputs. | |
| Modificada | Media (5) | 1.6% | — | Bitrix Site Manager | 19/5/2006 | 16/6/2026 | Bitrix Site Manager 4.1.x allows remote attackers to redirect users to other websites via a modified back_url during a HTTP POST request. NOTE: this issue has been referred to as "cross-site scripting," but that is inconsistent with the common use of the term. | |
| Modificada | Media (5) | 2.2% | — | Bitrix Site Manager | 19/5/2006 | 16/6/2026 | Bitrix Site Manager 4.1.x stores updater.log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Adcentrix Censtore | 18/4/2006 | 16/6/2026 | censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Netrix X-site Manager | 23/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Netrix X-Site Manager allows remote attackers to inject arbitrary web script or HTML via the product_id parameter, as originally demonstrated for a custom mp3players_details.php program. NOTE: the name of the affected program might be installation-dependent, but it has been… | |
| Modificada | Baja (2.1) | 0.44% | — | Citrix Program Neighborhood Client | 20/12/2005 | 16/6/2026 | Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field. | |
| Modificada | Alta (7.5) | 16% | — | Citrix ICA Program Neighborhood Client | 16/12/2005 | 16/6/2026 | Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response. | |
| Modificada | Media (4.3) | 1.4% | — | Citrix Metaframe Secure Access ManagerCitrix Nfuse | 3/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field. | |
| Modificada | Alta (7.5) | 2.1% | — | Citrix Metaframe | 4/10/2005 | 16/6/2026 | Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName). | |
| Modificada | Media (5) | 1.4% | — | Bitrix Site Manager | 15/6/2005 | 16/6/2026 | Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message. | |
| Modificada | Media (5) | 1.5% | — | Bitrix Site Manager | 15/6/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter. | |
| Modificada | Baja (2.1) | 0.37% | — | Citrix Metaframe Password Manager | 2/5/2005 | 16/6/2026 | Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. | |
| Modificada | Alta (7.5) | 1.3% | — | Citrix Metaframe Conferencing ManagerAI | 2/5/2005 | 16/6/2026 | Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse. | |
| Modificada | Baja (2.1) | 0.36% | — | Citrix Metaframe Password Manager | 31/12/2004 | 16/6/2026 | The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. | |
| Modificada | Alta (7.5) | 1.2% | — | Peersec Networks Matrixssl | 31/12/2004 | 16/6/2026 | PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session. | |
| Modificada | Media (5.8) | 0.79% | — | Peersec Networks Matrixssl | 31/12/2004 | 16/6/2026 | PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms… | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | Ultrix Dxterm | 20/12/2004 | 16/6/2026 | Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter. | |
| Modificada | Alta (7.5) | 3.8% | — | Citrix Metaframe ClientCitrix Program Neighborhood Agent | 26/4/2004 | 16/6/2026 | Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element. | |
| Modificada | Media (5) | 1.2% | — | Citrix Metaframe ClientCitrix Program Neighborhood Agent | 26/4/2004 | 16/6/2026 | Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive. | |
| Modificada | Media (5) | 1.8% | — | Matrix FTP ServerAI | 6/2/2004 | 16/6/2026 | Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command. |