Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
1092 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 3.8% | — | Snitz Communications Snitz Forums 2000 | 7/8/2003 | 16/6/2026 | password.asp en Snitz Forums 3.4.03 y anteriores permite a atacantes remotos reestablecer contraseñas y ganar privilegios de otros usuarios mediante una petición directa a password.asp con un identificador (id) de miembro modificado. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 7/8/2003 | 16/6/2026 | Vulnerabilidad de secuencias de comandos (XSS) en search.asp de Snitz Forums 3.4.03 y anteriores permite a atacantes remotos ejecutar script web arbitrario mediante el parámetro Search. | |
| Modificada | Alta (7.5) | 2.4% | — | Snitz Communications Snitz Forums 2000 | 16/6/2003 | 16/6/2026 | Vulnerabilidad de inyección de SQL en Snitz Forums 2000 anteriores a la 3.3.03 permite que atacantes remotos ejecuten procedimientos almacenados arbitrarios mediante la variable Email. | |
| Modificada | Media (5) | 1.9% | — | Blue World Communications Lasso WEB Data Engine | 31/12/2002 | 16/6/2026 | Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL. | |
| Modificada | Alta (10) | 2.1% | 💥 Exploit | Ruslan Communications Body Builder | 4/10/2002 | 16/6/2026 | SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | NEW Atlanta Communications Servletexec Isapi | 4/10/2002 | 16/6/2026 | The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message. | |
| Modificada | Media (5) | 8.3% | 💥 Exploit | NEW Atlanta Communications Servletexec Isapi | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | NEW Atlanta Communications Servletexec Isapi | 4/10/2002 | 16/6/2026 | NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet. | |
| Modificada | Media (4.6) | 0.43% | — | Hotline Communications Hotline Connect | 25/6/2002 | 16/6/2026 | Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 25/6/2002 | 16/6/2026 | Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 18/6/2002 | 16/6/2026 | members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL injection attack on the parameters (1) M_NAME, (2) UserName, (3) FirstName, (4) LastName, or (5) INITIAL. | |
| Modificada | Media (5) | 2.0% | — | Eshare Communications Inc. Eshare Expressions | 29/5/2002 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en eshare Expressions 4 Web server permite a atacantes remotos leer ficheros arbitrarios mediante un .. (punto punto) en la petición HTTP. | |
| Modificada | Alta (7.5) | 1.2% | — | Bell Communications Research S KEY | 2/9/2001 | 16/6/2026 | keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo. | |
| Modificada | Alta (7.5) | 2.6% | — | International Telecommunications Webbbs | 19/6/2000 | 16/6/2026 | Buffer overflow in WebBBS 1.15 allows remote attackers to execute arbitrary commands via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | SKY Communications Skyfull | 30/10/1999 | 16/6/2026 | Buffer overflow in Skyfull mail server via MAIL FROM command. | |
| Modificada | Media (5) | 1.3% | — | Blue World Communications Lasso CGI | 19/8/1997 | 16/6/2026 | Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.5) | 26% | 💥 Exploit | Apache Http ServerNetscape Commerce ServerNetscape Communications ServerNetscape Enterprise Server | 10/12/1996 | 16/6/2026 | List of arbitrary files on Web host via nph-test-cgi script. |