Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 2.0% | — | Zohocorp Manageengine Admanager Plus | 7/2/2018 | 17/6/2026 | /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted. | |
| Modificada | Media (4.3) | 3.6% | — | Zohocorp Manageengine Admanager Plus | 11/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ZOHO ManageEngine ADManager Plus before 6.2 Build 6270 allow remote attackers to inject arbitrary web script or HTML via the (1) technicianSearchText parameter to the Help Desk Technician page or (2) rolesSearchText parameter to the Help Desk Roles. | |
| Modificada | Alta (9.3) | 17% | 💥 Exploit | Freedownloadmanager Free Download Manager | 18/3/2014 | 17/6/2026 | Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download… | |
| Modificada | Media (6.8) | 0.95% | — | Lesterchan Wp-downloadmanager | 19/4/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Manageengine Admanager Plus | 13/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do. | |
| Modificada | Media (4.3) | 3.2% | — | Zohocorp Manageengine Admanager Plus | 23/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (10) | 8.0% | — | Ioquake3 EngineTremulousIourbanterrorWorldofpadman World OF Padman | 9/8/2011 | 16/6/2026 | The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL… | |
| Modificada | Alta (10) | 8.7% | — | Ioquake3 EngineOpenarenaSmokin-guns Smokin' GunsTremulous+2 | 4/8/2011 | 16/6/2026 | The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted… | |
| Modificada | Alta (7.5) | 4.2% | — | Ioquake3 EngineOpenarenaWorldofpadman World OF Padman | 4/8/2011 | 16/6/2026 | sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable. | |
| Modificada | Alta (7.1) | 1.7% | — | Freedownloadmanager Free Download Manager | 17/5/2010 | 16/6/2026 | Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file. | |
| Modificada | Alta (10) | 6.4% | — | Freedownloadmanager Free Download Manager | 17/5/2010 | 16/6/2026 | Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2) the websites feature in Site Explorer, (3) an FTP URI, or (4) a redirect. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | E-topbiz Admanager | 24/2/2009 | 16/6/2026 | SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter. | |
| Modificada | Media (6.5) | 0.86% | 💥 Exploit | Formfields Adman | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbitrary SQL commands via the campaignId parameter. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Dotnetindex Ikon Admanager | 16/12/2008 | 16/6/2026 | Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for ikonBAnner_AdManager.mdb. | |
| Modificada | Media (5.8) | 1.9% | 💥 Exploit | Gradman | 23/1/2008 | 16/6/2026 | Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361. | |
| Modificada | Media (4.3) | 2.8% | 💥 Exploit | Instituto Politicnico Nacional Gradman | 18/1/2008 | 16/6/2026 | Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Brain Book Software Adman | 26/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in login.php in AdMan 1.0.20051202 FF 3 patch and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pwd parameters. | |
| Modificada | Baja (2.6) | 1.2% | — | Site Trade ST Admanager Lite | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in publish.php in ST AdManager Lite allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, (3) article, (4) bio, and (5) name parameters. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Brain Book Software Adman | 24/3/2006 | 16/6/2026 | SQL injection vulnerability in viewStatement.php in AdMan 1.0.20051221 and earlier allows remote attackers to execute arbitrary SQL commands via the transactions_offset parameter. | |
| Modificada | Media (5) | 1.5% | — | Brain Book Software Adman | 24/3/2006 | 16/6/2026 | AdMan 1.0.20051221 and earlier allows remote attackers to obtain the full path via (1) a blank campaignId parameter to editCampaign.php and (2) a blank schemeId parameter to viewPricingScheme.php. |