Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Verlihub-project Verlihub Control Panel | 22/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html. | |
| Modificada | Media (6.9) | 0.79% | 💥 Exploit | Verlihub-project Verlihub | 22/12/2008 | 16/6/2026 | The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file. | |
| Modificada | Alta (9.3) | 5.4% | 💥 Exploit | Verlihub-project Verlihub | 22/12/2008 | 16/6/2026 | The cTrigger::DoIt function in src/ctrigger.cpp in the trigger mechanism in the daemon in Verlihub 0.9.8d-RC2 and earlier, when user triggers are enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in an argument. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Verlihub-project Verlihub Control Panel | 9/10/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the page parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Overlay Weaver | 30/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the DHT shell (owdhtshell) in Overlay Weaver 0.5.9 to 0.5.11, when invoked with the -x option, allows remote attackers to inject arbitrary web script or HTML via fields in certain input forms. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Verliadmin | 5/1/2007 | 16/6/2026 | Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then… | |
| Modificada | Alta (7.5) | 1.1% | — | Verliadmin | 20/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nick_mod or (2) nick parameter to (a) repass.php or (b) verify.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 1.1% | — | Verliadmin | 20/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in VerliAdmin 0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Verliadmin | 20/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to execute arbitrary PHP code via a URL in the q parameter. | |
| Modificada | Baja (2.1) | 0.35% | — | Watchguard Serverlock | 27/8/2003 | 16/6/2026 | WatchGuard ServerLock for Windows 2000 before SL 2.0.4 allows local users to access kernel memory via a symlink attack on \Device\PhysicalMemory. | |
| Modificada | Media (4.6) | 0.36% | — | Watchguard Serverlock | 27/8/2003 | 16/6/2026 | WatchGuard ServerLock for Windows 2000 before SL 2.0.3 allows local users to load arbitrary modules via the OpenProcess() function, as demonstrated using (1) a DLL injection attack, (2) ZwSetSystemInformation, and (3) API hooking in OpenProcess. | |
| Modificada | Alta (10) | 3.0% | — | Springer Verlag Berlin Heidelberg Simple Wais | 31/12/2002 | 16/6/2026 | Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character. |