Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Livecms | 20/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via an article name, possibly involving the titulo parameter in article.php. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Livecms | 20/6/2007 | 16/6/2026 | Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrary PHP code by specifying a PHP file type in a parameter intended for "a small image" associated with an article. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Livecms | 20/6/2007 | 16/6/2026 | SQL injection vulnerability in categoria.php in LiveCMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (9.3) | 3.1% | 💥 Exploit | Livecms | 20/6/2007 | 16/6/2026 | categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message. | |
| Modificada | Alta (9.3) | 7.8% | — | Corel Activecgm Browser | 14/6/2007 | 16/6/2026 | Multiple buffer overflows in acgm.dll in the Corel / Micrografx ActiveCGM Browser ActiveX control before 7.1.4.19 allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.5) | 1.3% | — | Activecampaign 1-2-all Broadcast Email | 11/5/2007 | 16/6/2026 | Incomplete blacklist vulnerability in filemanager/browser/default/connectors/php/config.php in the FCKeditor module, as used in ActiveCampaign 1-2-All (aka 12All) 4.50 through 4.53.13, and possibly other products, allows remote authenticated administrators to upload and possibly execute .php4 and .php5 files via… | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Activecalendar | 26/2/2007 | 16/6/2026 | Directory traversal vulnerability in data/showcode.php in ActiveCalendar 1.2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | |
| Modificada | Media (6.8) | 6.1% | 💥 Exploit | Activecalendar | 26/2/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ActiveCalendar 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the css parameter to (1) flatevents.php, (2) js.php, (3) mysqlevents.php, (4) m_2.php, (5) m_3.php, (6) m_4.php, (7) xmlevents.php, (8) y_2.php, or (9) y_3.php in data/. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Activecampaign Knowledgebuilder | 15/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131. | |
| Modificada | Media (4.6) | 2.1% | — | Adobe Livecycle Form Manager | 13/4/2006 | 16/6/2026 | Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, within the authentication system. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Activecampaign Supporttrio | 29/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module. | |
| Modificada | Media (5) | 1.5% | — | Activecampaign Supporttrio | 29/3/2006 | 16/6/2026 | ActiveCampaign SupportTrio 2.5 allows remote attackers to obtain the full path of the server via invalid (1) article or (2) print parameters in a kb action to index.php, or (3) an invalid category parameter to modules/KB/pdf.php, which leaks the path in an error message. | |
| Modificada | Alta (7.5) | 1.5% | — | Activecampaign 1-2-allActivecampaign GeneralActivecampaign IsalientActivecampaign Knowledgebuilder+2 | 3/3/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter. | |
| Modificada | Media (4) | 2.9% | — | Hauri LivecallHauri VirobotHauri Vrazmain.dll | 31/12/2005 | 16/6/2026 | Buffer overflow in the archive decompression library (vrAZMain.dll 5.8.22.137), as used in HAURI anti-virus products including (1) ViRobot Expert 4.0, (2) ViRobot Advanced Server, and (3) HAURI LiveCall, allows user-assisted attackers to execute arbitrary code via an ALZ archive containing a file with a long filename. | |
| Modificada | Alta (7.5) | 1.2% | — | Activecampaign Supporttrio | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Activecampaign Knowledgebuilder | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter. | |
| Modificada | Media (5) | 1.6% | — | Activecampaign SupporttrioAI | 26/11/2005 | 16/6/2026 | index.php in ActiveCampaign SupportTrio 1.4 and earlier allows remote attackers to read or include arbitrary files via the page parameter, possibly due to a directory traversal vulnerability. | |
| Modificada | Alta (7.8) | 1.8% | — | Activecampaign Knowledgebuilder | 26/11/2005 | 16/6/2026 | index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an invalid category parameter, which causes a large number of SQL queries to be processed. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Activecampaign 1-2-all Broadcast Email | 18/11/2005 | 16/6/2026 | SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel. | |
| Modificada | Alta (7.5) | 4.0% | — | Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server | 30/8/2005 | 16/6/2026 | Stack-based buffer overflow in the ACE archive decompression library (vrAZace.dll) in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall, when compressed file scanning is enabled, allows remote attackers to execute arbitrary code via an ACE archive that contains a… | |
| Modificada | Media (5) | 3.5% | — | Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server | 23/8/2005 | 16/6/2026 | Directory traversal vulnerability in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall allows remote attackers to overwrite arbitrary files via ".." sequences in filenames contained in (1) ACE, (2) ARJ, (3) CAB, (4) LZH, (5) RAR, (6) TAR and (7) ZIP files. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Liveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Activecampaign Knowledgebuilder | 31/12/2003 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Alta (7.5) | 4.3% | — | Critical Path Injoin Directory ServerCritical Path Livecontent Directory | 16/7/2001 | 16/6/2026 | Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite. | |
| Modificada | Alta (7.5) | 5.3% | — | Critical Path Injoin Directory ServerCritical Path Livecontent Directory | 16/7/2001 | 16/6/2026 | Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. |