Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
1028 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.5% | — | Phpbb Styles Extreme Styles Phpbb Module | 8/12/2005 | 16/6/2026 | Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter. | |
| Modificada | Media (5) | 5.2% | — | Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+4 | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details… | |
| Modificada | Baja (2.1) | 0.36% | — | Eduard Bloch Module-assistant | 20/10/2005 | 16/6/2026 | A rule file in module-assistant before 0.9.10 causes a temporary file to be created insecurely, which allows local users to conduct unauthorized operations. | |
| Modificada | Media (4.3) | 1.00% | — | Riverdark Studios RSS Syndicator Module | 27/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Firewall Services Module | 11/5/2005 | 16/6/2026 | Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs). | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Oxpus Phpbb Personal Notes Module | 3/5/2005 | 16/6/2026 | SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Datenbank Module | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Datenbank Module | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mod.php in the datenbank module for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (5) | 3.2% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets. | |
| Modificada | Media (5) | 1.6% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded. | |
| Modificada | Alta (7.2) | 0.40% | — | GNU Realtime Linux Security ModuleConectiva LinuxUbuntu Linux | 23/12/2004 | 16/6/2026 | The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. | |
| Modificada | Alta (7.5) | 1.3% | — | Easyweb Factory Subjects Module | 10/9/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Subjects 2.0 Postnuke module allow remote attackers to execute arbitrary SQL commands via the (1) pageid, (2) subid, or (3) catid parameters. | |
| Modificada | Media (5) | 1.2% | — | Phpnuke Video Gallery ModuleAI | 26/4/2004 | 16/6/2026 | modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message. | |
| Modificada | Baja (2.6) | 4.6% | 💥 Exploit | PostnukeAIPostnuke Downloads ModuleAIPostnuke WEB Links ModuleAI | 21/4/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Error Manager Php-nuke Module | 18/3/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) pagetitle or (2) error parameters, or (3) certain parameters in the error log. | |
| Modificada | Media (5) | 1.5% | — | Warpspeed 4nalbum Module | 15/3/2004 | 16/6/2026 | 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to obtain sensitive information via a direct request to displaycategory.php, which reveals the path in an error message. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Warpspeed 4nalbum Module | 15/3/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to execute arbitrary PHP code by modifying the basepath parameter to reference a URL on a remote web server that contains fileFunctions.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Warpspeed 4nalbum Module | 15/3/2004 | 16/6/2026 | SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or perform unauthorized database operations via the gid parameter. | |
| Modificada | Media (5) | 1.4% | — | Cisco Catalyst 6500Cisco Catalyst 6500 Ws-svc-nam-1Cisco Catalyst 6500 Ws-svc-nam-2Cisco Catalyst 6500 Ws-x6380-nam+5 | 5/1/2004 | 16/6/2026 | Desbordamiento de búfer en el Módulo de Servicios de Cortafuegos Cisco (FWSM) en dispositivos de la seria Cisco Cayalyst 6500 y 7600 permiten a atacantes remotos causar una denegación de servicio (caída y recarga) mediante una petición HTTP auth para autenticación TACACS+ o RADIUS. | |
| Modificada | Media (5) | 1.3% | — | Cisco Catalyst 6500Cisco Catalyst 6500 Ws-svc-nam-1Cisco Catalyst 6500 Ws-svc-nam-2Cisco Catalyst 6500 Ws-x6380-nam+5 | 5/1/2004 | 16/6/2026 | El Módulo de Servicios de Cortafuegos Cisco (FWSM) en dispositivos de la seria Cisco Cayalyst 6500 y 7600 permite a atacantes remotos causar una denegación de servicio (caída y recarga) mediante SNMPv3 cuando está establecido snmp-server. | |
| Modificada | Alta (7.5) | 4.4% | — | Cisco Application AND Content Networking SoftwareCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content Distribution Manager 4670+5 | 5/1/2004 | 16/6/2026 | Desbordamiento de búfer en el módulo de autenticación de Cisco ACNS 4.x anteriores a 4.2.11, y 5.x anteriores a 5.0.5, permite a atacantes remotos ejecutar código arbitrario mediante una contraseña larga. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Nukestyles ViewpagePhpnuke Nukestyles Viewpage Module | 31/12/2003 | 16/6/2026 | Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read arbitrary files via a full pathname in the file parameter. NOTE: This was originally reported as an issue in PHP-Nuke 6.5, but this is an independent addon. |