Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Sql-ledger | 20/3/2007 | 16/6/2026 | Directory traversal vulnerability in am.pl in SQL-Ledger 2.6.27 only checks for the presence of a NULL (%00) character to protect against directory traversal attacks, which allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence in the login parameter. | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | LedgersmbSql-ledger | 20/3/2007 | 16/6/2026 | Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows remote attackers to run arbitrary executables and bypass authentication via a .. (dot dot) sequence and trailing NULL (%00) in the login parameter. NOTE: this issue was reportedly addressed in… | |
| Modificada | Alta (7.5) | 1.8% | — | LedgersmbSql-ledger | 13/3/2007 | 16/6/2026 | Unspecified vulnerability in admin.pl in SQL-Ledger before 2.6.26 and LedgerSMB before 1.1.9 allows remote attackers to bypass authentication via unknown vectors that prevents a password check from occurring. | |
| Modificada | Alta (9) | 3.4% | — | LedgersmbSql-ledger | 13/3/2007 | 16/6/2026 | Unspecified vulnerability in LedgerSMB before 1.1.5 and SQL-Ledger before 2.6.25 allows remote attackers to overwrite files and possibly bypass authentication, and remote authenticated users to execute unauthorized code, by calling a custom error function that returns from execution. | |
| Modificada | Alta (10) | 5.2% | — | LedgersmbSql-ledger | 7/3/2007 | 16/6/2026 | Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before 1.1.5, allows remote attackers to read and overwrite arbitrary files, and execute arbitrary code, via . (dot) characters adjacent to (1) users and (2) users/members strings, which are removed by blacklisting functions that filter these strings and… | |
| Modificada | Media (6.5) | 1.9% | — | LedgersmbSql-ledger | 2/2/2007 | 16/6/2026 | The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872. | |
| Modificada | Alta (7.5) | 1.8% | — | DWS Systems Inc. Sql-ledger | 18/12/2006 | 16/6/2026 | login.pl in SQL-Ledger before 2.6.21 and LedgerSMB before 1.1.5 allows remote attackers to execute arbitrary Perl code via the "-e" flag in the script parameter, which is used as an argument to the perl program. | |
| Modificada | Alta (7.5) | 1.2% | — | Ledgersmb | 27/10/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in LedgerSMB (LSMB) 1.1.0 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors in (1) OE.pm, (2) AM.pm, and (3) Form.pm. | |
| Modificada | Media (5) | 1.3% | — | DWS Systems Inc. Sql-ledger | 14/9/2006 | 16/6/2026 | SQL-Ledger before 2.4.4 stores a password in a query string, which might allow context-dependent attackers to obtain the password via a Referer field or browser history. | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | DWS Systems Inc. Sql-ledgerLedgersmb | 13/9/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash). | |
| Modificada | Alta (7.5) | 1.8% | — | Sql-ledger | 31/8/2006 | 16/6/2026 | SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value. | |
| Modificada | Alta (10) | 9.6% | — | Checkmark PayrollCheckmark MultiledgerInnermedia Dynazip LibraryRealnetworks Realone Player+1 | 10/1/2005 | 16/6/2026 | Buffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2)… |