Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
998 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | — | Redhat SysreportRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Linux Advanced Workstation | 13/6/2005 | 16/6/2026 | sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Bluecoat Reporter | 24/5/2005 | 16/6/2026 | Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license. | |
| Modificada | Media (4.6) | 1.2% | 💥 Exploit | Bluecoat Reporter | 24/5/2005 | 16/6/2026 | templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true. | |
| Modificada | Media (4.3) | 1.3% | — | Bluecoat Reporter | 24/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page. | |
| Modificada | Media (4.3) | 0.95% | — | Eric Fichot BUG Report | 14/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php. | |
| Modificada | Media (4.3) | 11% | 💥 Exploit | Oracle 10G Reports Server | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Storeportal | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter. | |
| Modificada | Baja (2.1) | 0.36% | — | Debian Reportbug | 28/2/2005 | 16/6/2026 | reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords. | |
| Modificada | Baja (2.1) | 0.42% | — | Debian Reportbug | 28/2/2005 | 16/6/2026 | reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Webtrends Reporting Center | 31/12/2004 | 16/6/2026 | viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | 2wire Homeportal | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | BEA Weblogic ServerBorland Software J BuilderBusinessobjects Crystal EnterpriseBusinessobjects Crystal Enterprise Java SDK+5 | 6/8/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en los visores web de Business Objects Crystal Reports 9 and 10, y Crystal Enterprise 9 o 10, usados en Visual Studio .NET 2003 y Outlook 2003 con Business Contact Manager, Microsoft Business Solutions CRM 1.2, y otros productos, permiten a atacantes remotos leer y… | |
| Modificada | Media (5) | 1.6% | — | Businessobjects Crystal EnterpriseBusinessobjects Crystal Reports | 2/5/2004 | 16/6/2026 | The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder. | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | El comando COM_CHANGE_USER en MySQL 3.x anteriores a 2.23.54 y 4.x anterior a 4.0.6 permite a atacantes remotos ejecutar código arbitrario mediante una respuesta larga. | |
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | El comando COM_CHANGE_USER en MySQL 3.x anterirores de 3.23.54 y 4.x anteriores a 4.0.5 permite a atacantes remotos ganar privilegios mediante un ataque de fuerza bruta usando una contraseña de un carácter, lo que hace que MySQL compare la contraseña suministrada sólo con el primer carácter de la contraseña real. | |
| Modificada | Alta (7.5) | 6.8% | — | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | La librería de cliente libmysqlclient en MySQL 3.x a 3.23.54 y 4.x a 4.06, no verifica adecuadamente longitudes de campos de ciertas respuestas en las rutinas read_rows o read_one_row, lo que permite a a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario. | |
| Modificada | Media (5) | 5.4% | 💥 Exploit | Oracle Application ServerOracle Reports | 4/10/2002 | 16/6/2026 | rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks. | |
| Modificada | Alta (7.5) | 9.5% | — | Oracle Application ServerOracle Reports | 4/10/2002 | 16/6/2026 | Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Webtrends Reporting Center | 18/6/2002 | 16/6/2026 | Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute arbitrary code via a long HTTP GET request to the /reports/ directory. | |
| Modificada | Media (5) | 1.5% | — | Webtrends Reporting Center | 18/6/2002 | 16/6/2026 | WebTrends Reporting Center 4.0d allows remote attackers to determine the real path of the web server via a GET request to get_od_toc.pl with an empty Profile parameter, which leaks the pathname in an error message. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Webtrends Enterprise Reporting ServerWebtrends Enterprise Reporting Server NT | 20/9/2001 | 16/6/2026 | WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20). | |
| Modificada | Alta (10) | 4.0% | — | Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+11 | 12/3/2001 | 16/6/2026 | Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. | |
| Modificada | Alta (7.5) | 4.0% | — | Businessobjects Crystal Reports | 10/1/2001 | 16/6/2026 | Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords. |