Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (1.7) | 0.39% | — | Auditwizard | 8/9/2006 | 16/6/2026 | AuditWizard 6.3.2, when using "Remote Audit," logs the administrator password in plaintext to LaytonCmdSvc.log, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Alta (7.5) | 1.2% | — | PHP Labs Survey Wizard | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter. | |
| Modificada | Media (5) | 1.1% | — | Thesitewizard.com Chfeedback.pl Feedback Form Perl Script | 8/9/2005 | 16/6/2026 | CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers. | |
| Modificada | Media (5) | 2.6% | — | Intel CLI Auto-configuration UtilityIntel Client System Setup UtilityIntel Server Configuration WizardIntel Server Control+18 | 31/12/2004 | 16/6/2026 | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled. | |
| Modificada | Media (5) | 1.3% | — | Coffeecup Software Coffeecup Password Wizard | 31/12/2003 | 16/6/2026 | CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file. | |
| Modificada | Media (5) | 1.8% | — | Datawizard Ftpxq | 31/12/2002 | 16/6/2026 | Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name. | |
| Modificada | Media (6.4) | 1.5% | — | Datawizard Ftpxq | 18/12/2001 | 16/6/2026 | The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder. | |
| Modificada | Media (5) | 8.5% | 💥 Exploit | Datawizard Webxq | 27/6/2001 | 16/6/2026 | Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Datawizard Ftpxq | 3/5/2001 | 16/6/2026 | Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command. | |
| Modificada | Alta (7.5) | 2.1% | — | Systemsoft Systemwizard | 31/12/1999 | 16/6/2026 | SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2)… | |
| Modificada | Alta (10) | 9.7% | 💥 Exploit | Network Security Wizards Dragon-fire IDS | 5/8/1999 | 16/6/2026 | dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters. |