Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 4.2% | 💥 Exploit | Java Search Engine | 3/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (4.3) | 2.5% | — | Google API Search | 29/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Google API Search 1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the REQ parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Scripts-templates Allweb Search | 29/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Wwwsearchsolutions Revenuepilot Search Engine Script | 29/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RevenuePilot Search Engine Script 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the REQ parameter, which is used when performing a search. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Turn-k K-search | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in K-Search 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) term, (2) id, (3) stat, and (4) source parameters to index.php, and (5) through the image parameters with an add request. | |
| Modificada | Media (4.3) | 1.4% | — | Wwwsearchsolutions Searchfeed Search Engine | 29/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search. | |
| Modificada | Media (4.3) | 2.3% | — | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will be executed in the resulting error message. | |
| Modificada | Alta (7.5) | 41% | 💥 Exploit | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2)… | |
| Modificada | Media (5) | 1.8% | — | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports. | |
| Modificada | Media (4.3) | 19% | — | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a malicious XSLT style sheet. | |
| Modificada | Media (5) | 3.6% | — | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to determine the existence of arbitrary files via a relative path from a style sheet directory, then comparing the resulting error messages. | |
| Modificada | Media (4.3) | 0.95% | — | Unicode Msearch | 21/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Unicode version of msearch (unicode-msearch) 1.51(U1)-beta1, 1.51(U1), and 1.52(U1) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Search Enhanced | 30/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Phpsitesearch | 27/7/2005 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en "search.php" en PHPSiteSearch 1.7.7d permite que atacantes remotos inyecten script web arbitrario o HTML mediante el parámetro "query". | |
| Modificada | Media (4.3) | 1.2% | — | Kryloff Technologies Subject Search Server | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Kryloff Technologies Subject Search Server (SSServer) 1.1 allows remote attackers to inject arbitrary web script or HTML via the "Search For" field. | |
| Modificada | Alta (7.5) | 2.8% | — | IsearchAI | 31/12/2004 | 16/6/2026 | PHP file include injection vulnerability in isearch.inc.php for iSearch allows remote attackers to execute arbitrary code via the isearch_path parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Scripts FOR Educators Sillysearch | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SillySearch 2.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Mnogosearch | 10/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in mnoGoSearch 3.2.26 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) next and (2) prev result search pages, and the (3) extended and (4) simple search forms. | |
| Modificada | Alta (10) | 5.2% | — | Mnogosearch | 23/11/2004 | 16/6/2026 | Desbordamiento de búfer en la función UdmDocTextBuf de mnoGoSearch 3.2.13 a 3.2.15 podría permitir a un atacante remoto ejecutar código de su elección indexando un documento grande. | |
| Modificada | Alta (7.2) | 0.34% | — | EsearchAI | 6/8/2004 | 16/6/2026 | eupdatedb en esearch 0.6.1 y anteriores permite a usuarios locales crear ficheros de su elección mediante un ataque de enlaces simbólicos en el fichero temporal eseachdb.py.tmp. | |
| Modificada | Crítica (9.8) | 5.7% | 💥 Exploit | RisearchRisearch PRO | 27/7/2004 | 16/6/2026 | RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbitrary local files, by setting the url parameter to a (1) http://, (2) ftp://, or (3) file:// URL. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Wrensoft Zoom Search Engine | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows remote attackers to inject arbitrary web script or HTML via the zoom_query parameter. | |
| Modificada | Alta (7.8) | 1.7% | — | RIT Research Labs Tinyweb | 31/12/2003 | 16/6/2026 | TinyWeb 1.9 allows remote attackers to cause a denial of service (CPU consumption) via a ".%00." in an HTTP GET request to the cgi-bin directory. | |
| Modificada | Alta (7.5) | 0.70% | — | Research Triangle Software Cryptobuddy | 31/12/2003 | 16/6/2026 | RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers to guess the passphrase. | |
| Modificada | Alta (7.5) | 1.1% | — | Research Triangle Software Cryptobuddy | 31/12/2003 | 16/6/2026 | RTS CryptoBuddy 1.2 and earlier truncates long passphrases without warning the user, which may make it easier to conduct certain brute force guessing attacks. |