Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
–

1063 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.4%—Hosting Controller7/3/200516/6/2026
The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.
ModificadaMedia (5)1.5%—Hosting Controller7/3/200516/6/2026
Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.
ModificadaAlta (7.2)0.47%—Aladdin Enterprises Ghostscript9/2/200516/6/2026
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.
ModificadaMedia (5)2.9%💥 ExploitHosting Controller10/1/200516/6/2026
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.
ModificadaMedia (5)3.3%💥 ExploitRedstorm Desert SiegeRedstorm Ghost ReconRedstorm THE SUM OF ALL Fears31/12/200416/6/2026
Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly check return values from certain functions, which allows remote attackers to cause a denial of service (hang) via packets that contain text strings with incorrect size…
ModificadaAlta (7.5)1.2%—Webhost Automation Helm Control Panel31/12/200416/6/2026
SQL injection vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary SQL commands via the messageToUserAccNum parameter.
ModificadaMedia (4.3)1.8%💥 ExploitWebhost Automation Helm Control Panel31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the compose message form in HELM 3.1.19 and earlier allows remote attackers to execute arbitrary web script or HTML via the Subject field.
ModificadaMedia (4.3)1.1%—Chaogic Systems Vhost31/12/200416/6/2026
Unknown cross-site scripting (XSS) vulnerability in the web GUI in vHost before 3.10r1 has unknown impact and attack vectors.
ModificadaMedia (4.3)1.9%💥 ExploitPsychostats31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in login.php in PsychoStats 2.2.4 Beta and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.
ModificadaAlta (7.5)2.4%💥 ExploitPhpmywebhosting31/12/200416/6/2026
SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter.
ModificadaMedia (5)1.2%—Brickhost Phpscheduleit31/12/200416/6/2026
Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.
ModificadaAlta (7.5)1.1%—Brickhost Phpscheduleit31/8/200416/6/2026
phpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical access to gain administrative privileges.
ModificadaMedia (4.3)1.3%—Brickhost Phpscheduleit31/8/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Lastname fields during new user registration, or (3) the Schedule Name field.
ModificadaAlta (10)4.6%—Cisco Wireless LAN Solution EngineCisco Hosting Solution Engine1/6/200416/6/2026
Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration.
ModificadaMedia (4.6)0.38%—Broadcom Unicenter Remote Control Host5/1/200416/6/2026
"Vulnerabilidad de seguridad de sistema" desconocida en Computer Associates (CA) Unicenter Remote Control (URC) 6.0 permite a atacantes ganar privilegios mediante el interfaz de ayuda.
ModificadaMedia (5)1.3%—Broadcom Unicenter Remote Control Host5/1/200416/6/2026
Vulnerabilidad de "ataque de denegación de servicio" desconocida en Computer Associates (CA) Unicenter Remote Control (URC) 6.0 permite a atacantes causar una denegación de servicio (consumición de CPU en anfitrión del servicio URC).
ModificadaMedia (4.3)0.94%—Nukedweb Guestbookhost31/12/200316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the guestbook.
ModificadaAlta (7.5)2.4%—GhostviewGV17/11/200316/6/2026
gv 3.5.8, y posiblemente versiones anteriores, permite a atacantes remotos ejecutar comandos arbitrarios mediante metacaractéres de shell en el nombre de fichero de un fichero PDF o GZIP.
ModificadaMedia (4.6)2.0%💥 ExploitGGVGhostviewGV10/10/200216/6/2026
Desbordamiento de Buffer en gv 3.5.8 y anteriores, y gvv 1.0.2 y anteriores, que permite a los atacantes la ejecución arbitraria de código vía ficheros PDF o PostScript con caberceras erroneas al ser procesadas por una llamada sscanf no segura.
ModificadaAlta (10)2.7%—Hosting Controller12/8/200216/6/2026
Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password is not changed.
ModificadaAlta (10)4.0%—Hosting Controller12/8/200216/6/2026
Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.
ModificadaAlta (7.5)1.8%—Hosting Controller12/8/200216/6/2026
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
ModificadaMedia (6.4)2.3%—Hosting Controller12/8/200216/6/2026
Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor.asp, (2) folderactions.asp, or (3) editoractions.asp.
ModificadaMedia (5)8.3%💥 ExploitHosting Controller12/8/200216/6/2026
browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.
ModificadaMedia (6.4)9.2%💥 ExploitHosting Controller12/8/200216/6/2026
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parameter.
Orbitaley — Vulnerabilidades