Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3089▲ 499 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1024 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Dragon Internet Events Listing | 22/11/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en Dragon Calendar / Events Listing 2.x permite a un atacante remto ejecuvar comandos SQL de su elección a través de los parámetros (1) username o (2) password a (a) admin_login.asp, el (3) parámetro ID a (b) event_searchdetail.asp, o el parámetro (4) VenueID a (c)… | |
| Modificada | Baja (2.1) | 0.41% | — | DragonflybsdFreebsdMidnightbsdNetbsd+1 | 21/11/2006 | 16/6/2026 | Error de presencia de signo en entero en la función fw_ioctl (FW_IOCTL) en los controladores (dev/firewire/fwdev.c) FireWire (IEEE-1394) en varios núcleos de BSD, incluyendo DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT anterior al 15/11/2006, NetBSD-current anterior al 16/11/2006, NetBSD-4 anterior al… | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | PHP Blue Dragon | 23/9/2006 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados (XSS) en index.php Php Blue Dragon 2.9.1 y anteriores, permite a un atacante remoto inyectar secuencias de comandos web o HTML de su elección a través del parámetro m, el cual se refleja en un mensaje de error como resultado de un fallo en una consulta SQL. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | PHP Blue Dragon | 23/9/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en la función GetModuleConfig en public_includes/pub_kernel/pbd_modules.php en Php Blue Dragon 2.9.1 y anteriores, permite a un atacante remoto ejecutar comandos SQL de su elección a través del parámetro m en index.php. | |
| Modificada | Media (6.4) | 3.3% | 💥 Exploit | PHP Blue Dragon | 23/9/2006 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en pbd_engine.php en Php Blue Dragon 2.9.1 y anteriores permite a un atacante remoto leer y ejecutar código archivos de su elección a través de la secuencia ..(punto punto) a través del parámetro phpExt, como se demuestra con la ejecución de código PHP en un fichero… | |
| Modificada | Media (6.8) | 1.3% | — | Cpg-nuke Dragonfly CMS | 16/8/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Dragonfly CMS 9.0.6.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del campo search. | |
| Modificada | Media (4.3) | 2.9% | — | Dkscript Dragons Kingdom Script | 13/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en DKScript.com Dragon's Kingdom Script 1.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante un URI javascript en el atributo SRC de un elemento IMG en los campos (1) Subject y (2) Message en una… | |
| Modificada | Baja (2.6) | 1.2% | — | NEW Atlanta Communications Bluedragon ServerNEW Atlanta Communications Bluedragon Server JX | 26/6/2006 | 16/6/2026 | ulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en BlueDragon Server y Server JX v6.2.1.286 para Windows permite a atacantes remotos inyectar código web o HTML de su elección a través del nombre de fichero en una petición en un fichero (1) .cfm o (2) .cfml, que refleja el resultado en una página de… | |
| Modificada | Media (5) | 6.8% | 💥 Exploit | NEW Atlanta Communications Bluedragon ServerNEW Atlanta Communications Bluedragon Server JX | 26/6/2006 | 23/9/2026 | BlueDragon Server y Server JX v6.2.1.286 para Windows permite a atacantes remotos causar una denegación de servicio (cuelgue) a traves de una petición para un fichero .cfm cuyo nombre contiene un nombre de dispositivo MS-DOS como (1) con, (2) aux, (3) com1, y (4) com2. | |
| Modificada | Media (6.4) | 2.6% | 💥 Exploit | Phpbluedragon CMS | 19/6/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo PHP en software_upload/public_includes/pub_templates/vphptree/template.php en PhpBlueDragon CMS v2.9.1, permite a atacantes remotos ejecutar código PHP de su elección a través de la URL en el parámetro vsDragonRootPath. | |
| Modificada | Media (6.4) | 7.7% | 💥 Exploit | PHP Blue Dragon | 16/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in public_includes/pub_popup/popup_finduser.php in PHP Blue Dragon Platinum 2.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Cpg-nuke Dragonfly CMS | 7/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the username filed parameter to the (a) Your_Account module, (5) catid, (6) sid, (7) Story Text or (8) Extended text text fields… | |
| Modificada | Media (4.3) | 1.7% | — | Cpg-nuke Dragonfly CMS | 16/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in linking.php in CPG-Nuke Dragonfly CMS 9.0.6.1 allows remote attackers to inject arbitrary web script or HTML via a URI that is generated when creating a list of online users. | |
| Modificada | Alta (7.5) | 8.4% | 💥 Exploit | Cpg-nuke Dragonfly CMS | 10/2/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in (1) the newlang parameter and (2) the installlang parameter in a… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Dragoran Portal Module | 2/2/2006 | 16/6/2026 | SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.43% | — | DragonflyFreebsdLinux KernelOpenbsd | 31/12/2005 | 16/6/2026 | The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the system is running. | |
| Modificada | Media (5) | 1.4% | — | Incredible Interactive Dragonfly Commerce | 12/7/2005 | 16/6/2026 | Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed this issue, saying that "Dragonfly… | |
| Modificada | Alta (7.5) | 1.1% | — | Incredible Interactive Dragonfly Commerce | 12/7/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6)… | |
| Modificada | Alta (10) | 2.3% | — | DragonflybsdFreebsd | 2/5/2005 | 16/6/2026 | The sendfile system call in FreeBSD 4.8 through 4.11 and 5 through 5.4 can transfer portions of kernel memory if a file is truncated while it is being sent, which could allow remote attackers to obtain sensitive information. | |
| Modificada | Media (4.3) | 0.94% | — | Cpg-nuke CPG Dragonfly CMS | 26/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CPG Dragonfly 9.0.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the profile parameter to index.php or (2) the cat parameter. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Cisco Catalyst 6000 Intrusion Detection System ModuleCisco Secure Intrusion Detection SystemISS Realsecure Network SensorISS Realsecure Server Sensor+2 | 30/10/2001 | 16/6/2026 | Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for… | |
| Modificada | Media (5) | 1.9% | — | Shadow OP Software Dragon Server | 16/6/2000 | 16/6/2026 | Dragon FTP server allows remote attackers to cause a denial of service via a long USER command. | |
| Modificada | Media (5) | 4.6% | 💥 Exploit | Shadow OP Software Dragon Server | 16/6/2000 | 16/6/2026 | Dragon telnet server allows remote attackers to cause a denial of service via a long username. | |
| Modificada | Alta (10) | 9.7% | 💥 Exploit | Network Security Wizards Dragon-fire IDS | 5/8/1999 | 16/6/2026 | dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters. |