Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2685▼ 177 respecto a la semana anterior
Críticas / altas1223▼ 305 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
1046 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.8% | 💥 Exploit | 2wire INC Homeportal2wire INC Officeportal | 1/9/2006 | 16/6/2026 | La interfaz de administración basada en web en los modems y routers de la serie HomePortal y OfficePortal de 2Wire, Inc. permite a atacantes remotos provocar una denegación de servicio (caída) mediante una secuencia CRLF en una petición GET. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Phome Empire CMS | 27/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en e/class/CheckLevel.php en Phome Empire CMS 3.7 y anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro check_path. | |
| Modificada | Crítica (9.8) | 1.8% | — | Mambo MTG Myhomepage Component | 21/8/2006 | 16/6/2026 | ** IMPUGNADA ** Múltiples vulnerabilidades de inclusión remota de archivo en PHP en el componente lmtg_myhomepage (com_lmtg_myhomepage) para Mambo permiten a atacantes remotos ejecutar código PHP de su eleccion mediante una URL en el parámetro mosConfig_absolute_path en (1) install.lmtg_homepage.php y… | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | User Home Pages | 5/8/2006 | 16/6/2026 | Múltiples vulnerabilidades PHP de inclusión remota de archivo en (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, y (7) uninstall.uhp.php, en el componente UHP (User Home Pages) 0.5 (también conocido como com_uhp) para Mambo o Joomla,… | |
| Modificada | Media (6.8) | 34% | 💥 Exploit | Mcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+5 | 1/8/2006 | 16/6/2026 | Desbordamiento de búfer en control ActiveX McSubMgr (mcsubmgr.dll) en McAfee Security Center 6.0.23 para Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, y QuickClean permite a atacantes con la intervención del usuario ejecutar… | |
| Modificada | Media (5) | 1.2% | — | Professional Home Page Tools Guestbook | 25/7/2006 | 16/6/2026 | delcookie.php de Professional Home Page Tools Guestbook cambia la fecha de caducidad de una cookie en lugar de borrar el valor de la cookie, lo cual facilita a los atacantes robar la cookie y obtener el resumen (hash) de la contraseña de administrador después de la desconexión. | |
| Modificada | Alta (7.5) | 1.5% | — | Professional Home Page Tools Guestbook | 21/7/2006 | 16/6/2026 | Múltilpes vulnerabilidades de inyección SQL en class.php en Professional Home Page Tools Guestbook permite a atacantes remotos ejecutar comandos SQL de su elección a través de los parámetros (1) hidemail, (2) name, (3) mail, (4) ip, o (5) text. | |
| Modificada | Media (6.4) | 1.2% | — | Professional Home Page Tools Guestbook | 21/7/2006 | 16/6/2026 | setcookie.php para el login de administrador en Professional Home Page Tools Guestbook registra la hash de la contraseña del administrador en una cookie, el cual permite a atacantes conducir un ataque por fuerza bruta para adivinar la contraseña después de obtener el hash. | |
| Modificada | Baja (2.6) | 1.2% | — | Cescripts Realty Home Rent | 15/6/2006 | 16/6/2026 | Vulnerabilidad de Cross-site scripting (XSS) en index.php de Cescripts Realty Home Rent permite a atacantes remotos inyectar scripts web arbitrarios a través del parámetro sel_menu. NOTA: El fabricante notifica en CVE 20060823 : "Todos los problemas relacionado con este y otros en cescripts.com han sido tratados y… | |
| Modificada | Media (5) | 1.8% | — | Asteriskathome | 25/4/2006 | 16/6/2026 | Absolute path traversal vulnerability in recordings/misc/audio.php in the Asterisk Recording Interface (ARI) web interface in Asterisk@Home before 2.8 allows remote attackers to read arbitrary MP3, WAV, and GSM files via a full pathname in the recording parameter. NOTE: this issue can also be used to determine… | |
| Modificada | Alta (7.8) | 8.0% | 💥 Exploit | Asteriskathome | 25/4/2006 | 16/6/2026 | Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information. | |
| Modificada | Baja (2.6) | 1.3% | — | 4homepages 4images | 25/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php. | |
| Modificada | Alta (7.5) | 2.8% | — | HP CompaqhttpserverHP System Management Homepage | 13/4/2006 | 16/6/2026 | HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL. | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Htmljunction Ezhomepagepro | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d)… | |
| Modificada | Media (5) | 5.2% | — | HP System Management Homepage | 7/3/2006 | 16/6/2026 | Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | MY Little Homepage MY Little Weblog | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags. | |
| Modificada | Media (4.3) | 1.8% | — | MY Little Homepage MY Little Forum | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags. | |
| Modificada | Media (4.3) | 1.8% | — | MY Little Homepage MY Little Guestbook | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guestbook.php in my little homepage my little guestbook, as last modified in March 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags. | |
| Modificada | Media (5) | 1.7% | — | ARI Pikivirta Home FTP Server | 22/1/2006 | 16/6/2026 | Ari Pikivirta Home Ftp Server 1.0.7 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Helmsman Research Homeftp | 22/1/2006 | 16/6/2026 | Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | MY Little Homepage MY Little Forum | 24/9/2005 | 16/6/2026 | SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field. | |
| Modificada | Media (5) | 1.7% | — | ARI Pikivirta Home FTP Server | 30/8/2005 | 16/6/2026 | Directory traversal vulnerability in Home Ftp Server 1.0.7 allows remote authenticated users to read arbitrary files via "C:\" (Windows drive letter) sequences in commands such as (1) LIST or (2) RETR. |