Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1086 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.9% | — | Cisco Content Services Switch 11500 | 5/4/2006 | 16/6/2026 | Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid, but obsolete" or (2) "specially crafted" HTTP requests. | |
| Modificada | Alta (7.5) | 1.2% | — | Ideosoft Design Ideocontent Manager | 27/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in IdeoContent Manager allow remote attackers to execute arbitrary SQL commands via the (1) goto_id or (2) mid parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Ideosoft Design Ideocontent Manager | 27/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php. | |
| Modificada | Media (4.3) | 1.2% | — | Goldstag Content Management System | 27/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote attackers to inject arbitrary web script or HTML via the text parameter. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (5) | 2.4% | — | Cisco Application AND Content Networking SoftwareCisco ATACisco Subscriber Edge Services ManagerCisco IP Phone 7902+3 | 31/12/2005 | 16/6/2026 | Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect offset. | |
| Modificada | Alta (7.5) | 1.2% | — | Antharia Oncontent CMS | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Antharia OnContent // CMS allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it is not clear, but this might be an application service provider, in which case it might be excluded from CVE. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Paperthin Commonspot Content Server | 29/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter. | |
| Modificada | Media (5) | 1.4% | — | Paperthin Commonspot Content Server | 29/12/2005 | 16/6/2026 | PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting error message. | |
| Modificada | Media (4.3) | 1.2% | — | Nqcontent | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in NQcontent 3 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the text parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Contentserv | 20/12/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en index.php en ContentServ 3.1 y anteriores permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro "StoryID". | |
| Modificada | Alta (7.5) | 1.1% | — | Icms Content Management Systems Icms | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Icms Content Management Systems Icms | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Magnolia Content Management Suite | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.html in Magnolia Content Management Suite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (5.8) | 1.7% | 💥 Exploit | HOT Banana WEB Content Management Suite | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana Web Content Management Suite 5.3 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | |
| Modificada | Baja (2.1) | 0.33% | — | IBM DB2 Content Manager | 16/11/2005 | 16/6/2026 | db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING." | |
| Modificada | Media (5) | 1.5% | — | Icms Content Management Systems Icms | 16/11/2005 | 16/6/2026 | PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter. | |
| Modificada | Media (5) | 1.4% | — | IBM DB2 Content Manager | 16/11/2005 | 16/6/2026 | INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files. | |
| Modificada | Media (4.6) | 0.40% | — | Sony First4internet XCP Content Management | 3/11/2005 | 16/6/2026 | The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that uses XCP. | |
| Modificada | Media (5) | 1.0% | — | Cisco Content Services Switch 11500 | 2/11/2005 | 16/6/2026 | Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation. | |
| Modificada | Media (6.4) | 1.9% | — | Contentserv | 27/9/2005 | 16/6/2026 | Directory traversal vulnerability in admin/about.php in contentServ 3.1 allows remote attackers to read or include arbitrary files via ".." sequences in the ctsWebsite parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Content2web | 21/9/2005 | 16/6/2026 | PHP file inclusion vulnerability in index.php in Content2Web 1.0.1 allows remote attackers to include arbitrary files via the show parameter, which can lead to resultant errors such as path disclosure, SQL error messages, and cross-site scripting (XSS). | |
| Modificada | Alta (7.5) | 1.9% | — | WEB Content Management News System | 7/8/2005 | 16/6/2026 | Web Content Management News System permite a atacantes remotos crear cuentas de su elección y ganar privilegios mediante una petición directa a Admin/Users/AddModifyInput.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | WEB Content Management News System | 7/8/2005 | 16/6/2026 | Vulnerabilidad de scritps en sitios cruzados (XSS) en Web Content Management News System permite a atacantes remotos inyectar script web arbitrario o HTML mediante el parámetro strRootpath de validsession.php o el parámetro strTable de Admin/News/List.php | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. |