Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
1063 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | Hosting Controller | 7/3/2005 | 16/6/2026 | The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field. | |
| Modificada | Media (5) | 1.5% | — | Hosting Controller | 7/3/2005 | 16/6/2026 | Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv. | |
| Modificada | Alta (7.2) | 0.47% | — | Aladdin Enterprises Ghostscript | 9/2/2005 | 16/6/2026 | The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Hosting Controller | 10/1/2005 | 16/6/2026 | Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Redstorm Desert SiegeRedstorm Ghost ReconRedstorm THE SUM OF ALL Fears | 31/12/2004 | 16/6/2026 | Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly check return values from certain functions, which allows remote attackers to cause a denial of service (hang) via packets that contain text strings with incorrect size… | |
| Modificada | Alta (7.5) | 1.2% | — | Webhost Automation Helm Control Panel | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Webhost Automation Helm Control Panel | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field. | |
| Modificada | Media (4.3) | 1.1% | — | Chaogic Systems Vhost | 31/12/2004 | 16/6/2026 | Unknown cross-site scripting (XSS) vulnerability in the web GUI in vHost before 3.10r1 has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Psychostats | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Phpmywebhosting | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter. | |
| Modificada | Media (5) | 1.2% | — | Brickhost Phpscheduleit | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations. | |
| Modificada | Alta (7.5) | 1.1% | — | Brickhost Phpscheduleit | 31/8/2004 | 16/6/2026 | phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges. | |
| Modificada | Media (4.3) | 1.3% | — | Brickhost Phpscheduleit | 31/8/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field. | |
| Modificada | Alta (10) | 4.6% | — | Cisco Wireless LAN Solution EngineCisco Hosting Solution Engine | 1/6/2004 | 16/6/2026 | Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration. | |
| Modificada | Media (4.6) | 0.38% | — | Broadcom Unicenter Remote Control Host | 5/1/2004 | 16/6/2026 | "Vulnerabilidad de seguridad de sistema" desconocida en Computer Associates (CA) Unicenter Remote Control (URC) 6.0 permite a atacantes ganar privilegios mediante el interfaz de ayuda. | |
| Modificada | Media (5) | 1.3% | — | Broadcom Unicenter Remote Control Host | 5/1/2004 | 16/6/2026 | Vulnerabilidad de "ataque de denegación de servicio" desconocida en Computer Associates (CA) Unicenter Remote Control (URC) 6.0 permite a atacantes causar una denegación de servicio (consumición de CPU en anfitrión del servicio URC). | |
| Modificada | Media (4.3) | 0.94% | — | Nukedweb Guestbookhost | 31/12/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the guestbook. | |
| Modificada | Alta (7.5) | 2.4% | — | GhostviewGV | 17/11/2003 | 16/6/2026 | gv 3.5.8, y posiblemente versiones anteriores, permite a atacantes remotos ejecutar comandos arbitrarios mediante metacaractéres de shell en el nombre de fichero de un fichero PDF o GZIP. | |
| Modificada | Media (4.6) | 2.0% | 💥 Exploit | GGVGhostviewGV | 10/10/2002 | 16/6/2026 | Desbordamiento de Buffer en gv 3.5.8 y anteriores, y gvv 1.0.2 y anteriores, que permite a los atacantes la ejecución arbitraria de código vía ficheros PDF o PostScript con caberceras erroneas al ser procesadas por una llamada sscanf no segura. | |
| Modificada | Alta (10) | 2.7% | — | Hosting Controller | 12/8/2002 | 16/6/2026 | Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed. | |
| Modificada | Alta (10) | 4.0% | — | Hosting Controller | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Hosting Controller | 12/8/2002 | 16/6/2026 | getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix. | |
| Modificada | Media (6.4) | 2.3% | — | Hosting Controller | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor.asp, (2) folderactions.asp, or (3) editoractions.asp. | |
| Modificada | Media (5) | 8.3% | 💥 Exploit | Hosting Controller | 12/8/2002 | 16/6/2026 | browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter. | |
| Modificada | Media (6.4) | 9.2% | 💥 Exploit | Hosting Controller | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parameter. |