Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

86 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (1.7)0.39%—Auditwizard8/9/200616/6/2026
AuditWizard 6.3.2, when using "Remote Audit," logs the administrator password in plaintext to LaytonCmdSvc.log, which allows local users to obtain sensitive information by reading the file.
ModificadaAlta (7.5)1.2%—PHP Labs Survey Wizard1/12/200516/6/2026
SQL injection vulnerability in survey.php in PHP Labs Survey Wizard allows remote attackers to execute arbitrary SQL commands via the sid parameter.
ModificadaMedia (5)1.1%—Thesitewizard.com Chfeedback.pl Feedback Form Perl Script8/9/200516/6/2026
CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers.
ModificadaMedia (5)2.6%—Intel CLI Auto-configuration UtilityIntel Client System Setup UtilityIntel Server Configuration WizardIntel Server Control+1831/12/200416/6/2026
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.
ModificadaMedia (5)1.3%—Coffeecup Software Coffeecup Password Wizard31/12/200316/6/2026
CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file.
ModificadaMedia (5)1.8%—Datawizard Ftpxq31/12/200216/6/2026
Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name.
ModificadaMedia (6.4)1.5%—Datawizard Ftpxq18/12/200116/6/2026
The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.
ModificadaMedia (5)8.5%💥 ExploitDatawizard Webxq27/6/200116/6/2026
Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack.
ModificadaMedia (5)6.5%💥 ExploitDatawizard Ftpxq3/5/200116/6/2026
Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.
ModificadaAlta (7.5)2.1%—Systemsoft Systemwizard31/12/199916/6/2026
SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2)…
ModificadaAlta (10)9.7%💥 ExploitNetwork Security Wizards Dragon-fire IDS5/8/199916/6/2026
dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.
Orbitaley — Vulnerabilidades