Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Tikiwiki Cms/groupware | 1/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Horde GroupwareHorde | 25/9/2012 | 16/6/2026 | Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November 2011 and February 2012, contains an externally introduced modification (Trojan Horse) in templates/javascript/open_calendar.js, which allows remote attackers to execute arbitrary PHP code. | |
| Modificada | Media (5.8) | 1.5% | — | EgroupwareEgroupware Enterprise Line | 31/8/2012 | 16/6/2026 | Open redirect vulnerability in phpgwapi/ntlm/index.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter. | |
| Modificada | Media (4.3) | 1.4% | — | EgroupwareEgroupware Enterprise Line | 31/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpgwapi/js/jscalendar/test.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | EgroupwareEgroupware Enterprise Line | 31/8/2012 | 16/6/2026 | SQL injection vulnerability in phpgwapi/js/dhtmlxtree/samples/with_db/loaddetails.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 2.3% | — | EgroupwareEgroupware Enterprise Line | 31/8/2012 | 16/6/2026 | Directory traversal vulnerability in admin/remote.php in EGroupware Enterprise Line (EPL) before 11.1.20110804-1 and EGroupware Community Edition before 1.8.001.20110805 allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in the type parameter. | |
| Modificada | Media (5) | 4.6% | 💥 Exploit | Tikiwiki Cms/groupware | 12/7/2012 | 16/6/2026 | TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php. | |
| Modificada | Crítica (9.8) | 63% | 💥 Exploit | Tikiwiki Cms/groupware | 12/7/2012 | 16/6/2026 | TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages,… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Simple-groupware Simplegroupware | 8/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in bin/index.php in SimpleGroupware 0.742 and other versions before 0.743 allows remote attackers to inject arbitrary web script or HTML via the export parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Horde Groupware Webmail Edition | 24/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde_Form in Horde Groupware Webmail Edition before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to email verification. NOTE: Some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 2.3% | — | Horde Dynamic IMPHorde IMPHorde Groupware Webmail Edition | 24/1/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Denaliintranet Brightsuite Groupware | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to execute arbitrary SQL commands via the ContactID parameter. | |
| Modificada | Media (4.3) | 0.90% | — | Horde IMPHorde Groupware | 4/4/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka fmusername), (2) password (aka fmpassword), or (3) server (aka fmserver) field… | |
| Modificada | Media (4.3) | 2.6% | — | Horde GroupwareHorde Dynamic IMP | 4/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via vectors related to displaying mailbox names. | |
| Modificada | Media (4.3) | 5.0% | 💥 Exploit | Horde IMPHorde Groupware | 31/3/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via the fm_id parameter in a fetchmail_prefs_save action, related to the Fetchmail configuration. | |
| Modificada | Media (4.3) | 3.3% | 💥 Exploit | Egroupware | 22/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | |
| Modificada | Alta (7.5) | 8.5% | 💥 Exploit | Egroupware | 22/9/2010 | 16/6/2026 | phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions before 1.6.003; and EPL 9.1 before 9.1.20100309 and 9.2 before 9.2.20100309; allows remote attackers to execute arbitrary commands via shell… | |
| Modificada | Alta (7.5) | 2.3% | — | Phpgroupware | 19/5/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpGroupWare (phpgw) before 0.9.16.016 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) class.sessions_db.inc.php, (2) class.translation_sql.inc.php, or (3) class.auth_sql.inc.php in phpgwapi/inc/. | |
| Modificada | Media (6.8) | 2.0% | — | Phpgroupware | 19/5/2010 | 16/6/2026 | Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Tikiwiki Cms/groupware | 27/3/2010 | 16/6/2026 | The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Tikiwiki Cms/groupware | 27/3/2010 | 16/6/2026 | The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse. | |
| Modificada | Alta (7.5) | 1.3% | — | Tikiwiki Cms/groupware | 27/3/2010 | 16/6/2026 | SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable. | |
| Modificada | Alta (7.5) | 1.4% | — | Tikiwiki Cms/groupware | 27/3/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php. | |
| Modificada | Media (4.3) | 2.3% | — | Phpgroupware | 24/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence. | |
| Modificada | Alta (7.5) | 3.4% | — | Phpgroupware | 24/12/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackers to (1) read arbitrary files via the csvfile parameter to addressbook/csv_import.php, or (2) include and execute arbitrary local files via the conv_type parameter in… |