Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 39% | — | Microsoft .net Framework | 10/10/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Microsoft .NET Framework 2.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante vectores no especificados implicando "controles ASP.NET que establecen la propiedad AutoPostBack a true". | |
| Modificada | Media (4.3) | 1.8% | — | Horde Application Framework | 21/8/2006 | 16/6/2026 | index.php en Horde Application Framework anerior a 3.1.2 permite a atacantes remotos incluir páginas web de otros sitios, lo que podría ser útil para ataques de phishing, mediante una URL en el parámetro url, también conocido como "referencia en sitios cruzados" (cross-site referencing). NOTA: algunas fuetnes se han… | |
| Modificada | Media (5) | 2.4% | — | Horde Application Framework | 13/7/2006 | 16/6/2026 | services/go.php en Horde Application Framework 3.0.0 hasta la 3.0.10 y 3.1.0 hasta la 3.1.1 no restringe de forma adecuada su capacidad de imagen de proxy, lo cual permite a atacantes remotos llevar a cabo ataques "Web tunneling" y utilizar el servidor como un proxy a través de la URL (1) http, (2) https, y (3) ftp en… | |
| Modificada | Media (5) | 37% | — | Microsoft .net Framework | 11/7/2006 | 16/6/2026 | Microsoft .NET framework 2.0 (ASP.NET) en Microsoft Windows 2000 SP4, XP SP1 y SP2, y Server 2003 hasta SP1, permite a atacantes remotos evitar las restricciones de acceso a través de "URL paths" no especificadas que pueden acceder a objetos Application Folder "explícitamente por nombre". | |
| Modificada | Media (5.1) | 16% | 💥 Exploit | Blueshoes Framework | 6/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) APP[path][applications] parameter to (a) Bs_Faq.class.php, (2) APP[path][core] parameter to (b) fileBrowserInner.php, (c) file.php, and (d) viewer.php, and (e)… | |
| Modificada | Media (4) | 14% | 💥 Exploit | Microsoft .net Framework | 30/3/2006 | 16/6/2026 | Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method. | |
| Modificada | Media (5.1) | 8.0% | — | Microsoft .net Framework | 30/3/2006 | 16/6/2026 | Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name. | |
| Modificada | Alta (7.5) | 39% | 💥 Exploit | Horde Application Framework | 29/3/2006 | 16/6/2026 | Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer. | |
| Modificada | Media (5) | 1.4% | — | Liquid Bytes Technologies Adaptive Website FrameworkAI | 20/12/2005 | 16/6/2026 | Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message. | |
| Modificada | Media (4.3) | 1.2% | — | Liquid Bytes Technologies Adaptive Website Framework | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in account.html in Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Baja (3.5) | 1.6% | — | Horde Application Framework | 13/12/2005 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Horde Application Framework anteriores a 3.0.8 permiten a usuarios remotos autenticados inyectar HTML o 'script' web de su elección mediante múltiples vectores, como se ha demostrado mediante (1) el campo identidad, (2) los campos de… | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | ATI Catalyst DriverMicrosoft .net FrameworkMicrosoft OfficeMicrosoft Project+2 | 19/8/2005 | 16/6/2026 | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the… | |
| Modificada | Media (5) | 1.2% | — | Metasploit Framework | 7/8/2005 | 16/6/2026 | La función StateToOptions en msfweb de Metasploit Framework 2.4 y anteriores, cuando corre con la opción -D (modo defanged, desdentado) permite a atacantes modificar variables de entorno temporales antes de que la opción de entorno "_Defanged" sea comprobada cuando se procesa la orden Exploit. | |
| Modificada | Media (5) | 1.8% | — | IBM Tivoli Management Framework | 11/7/2005 | 16/6/2026 | The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data. | |
| Modificada | Media (4.3) | 1.2% | — | Horde Application Framework | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title. | |
| Modificada | Media (4.3) | 16% | — | Microsoft .net FrameworkMono | 14/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<". | |
| Modificada | Media (5) | 1.5% | — | Hitachi Cosminexus Portal FrameworkAI | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library. | |
| Modificada | Media (4.3) | 1.3% | — | Horde Application Framework | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) module, (2) topic, or (3) module parameters. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria. | |
| Modificada | Alta (7.5) | 3.3% | — | IBM Tivoli Management Framework | 4/10/2002 | 16/6/2026 | Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 3.3% | — | IBM Tivoli Management Framework | 4/10/2002 | 16/6/2026 | Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (10) | 24% | — | Microsoft .net Framework | 26/7/2002 | 16/6/2026 | Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode. | |
| Modificada | Media (5) | 28% | — | Microsoft .net Framework | 26/7/2002 | 16/6/2026 | orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. | |
| Modificada | Alta (9) | 2.1% | — | IBM Tivoli Management Framework | 31/12/2000 | 23/9/2026 | La interfaz HTTP del Framework de Cliente Ligero de Tivoli (LCF) en IBM Tivoli Management Framework 3.7.1 establece http_disable en cero en el momento de la instalación, lo que permite a usuarios remotos autenticados eludir los permisos de archivo en los archivos de datos de configuración de Tivoli Endpoint mediante… |