Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
1099 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.6) | 1.5% | — | Research Triangle Software CryptobuddyMicrosoft ALL Windows | 31/12/2003 | 16/6/2026 | CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data. | |
| Modificada | Alta (7.5) | 0.95% | — | Research Triangle Software Cryptobuddy | 31/12/2003 | 16/6/2026 | RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the passphrase. | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Mnogosearch | 24/7/2003 | 16/6/2026 | Desbordamiento de búfer en search.cgi de mnoGoSearch 3.1.20 permite a atacantes remotos ejecutar código arbitrario mediante un parámetro ul largo. | |
| Modificada | Alta (7.5) | 9.0% | 💥 Exploit | Mnogosearch | 24/7/2003 | 16/6/2026 | Desbordamiento de búfer en search.cgi de mnoGoSearch 3.2.10 permite a atacantes remotos ejecutar código arbitrario mediante un parámetro tmplt largo. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Astaware SearchdiscSunone Starter KIT | 2/4/2003 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en ASTAware SearchDisk engine en Sun ONE Starter Kit 2.0 permite a atacantes remotos leer ficheros arbitrarios mediante un ataque de .. (punto punto)en los puertos 6015 ó 6016, o una ruta absoluta en el puerto 6017 | |
| Modificada | Media (5) | 2.3% | — | Mondosoft Mondosearch | 2/4/2003 | 16/6/2026 | MsmMask.exe en MondoSearch 4.4 permite a atacantes remotos obtener el código fuente de rutinas mediante el parámetro mask. | |
| Modificada | Media (5) | 9.2% | 💥 Exploit | Research Systems Inc. ION Script | 31/3/2003 | 16/6/2026 | Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (drive letter) or (2) .. (dot-dot) sequences in the page parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Verity Search97 | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Verity Search97 allows remote attackers to insert arbitrary web content and steal sensitive information from other clients, possibly due to certain error messages from template pages that use the (1) vformat or (2) vfilter functions. | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Independent Solution Simple Site SearcherIndependent Solution Super Site Searcher | 31/12/2002 | 16/6/2026 | site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | AGH Htmlsearch | 31/12/2002 | 16/6/2026 | search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the template parameter. | |
| Modificada | Alta (7.5) | 7.2% | 💥 Exploit | Zoltan Milosevic Fluid Dynamics Search Engine | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters. | |
| Modificada | Alta (7.5) | 2.8% | — | Matsushita Research Mnews | 4/10/2002 | 16/6/2026 | Múltiples desbordamientos de búfer en mnews 1.22 y anteriores permiten: a un servidor NNTP remoto ejecutar código arbitrario mediante respuestas largas, o a usuarios locales ganar privilegios mediante argumentos de línea de comando largos (-f, -n, -D, -M, -p), o mediante variables de entorno largas (JNAMES,… | |
| Modificada | Media (5) | 5.7% | 💥 Exploit | Wolfram Research Webmathematica | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the MSPStoreID parameter. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Cgiscript Cssearch Professional | 12/8/2002 | 16/6/2026 | csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup command and the setup parameter, which overwrites the setup.cgi configuration file that is loaded by csSearch.cgi. | |
| Modificada | Media (5.1) | 1.1% | — | Novell WEB Search | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter. | |
| Modificada | Alta (7.5) | 3.3% | — | Mnogosearch | 12/8/2002 | 16/6/2026 | Buffer overflow in search.cgi in mnoGoSearch 3.1.19 and earlier allows remote attackers to execute arbitrary code via a long query (q) parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Wolfram Research Mathematica | 13/2/2002 | 16/6/2026 | El gestor de licencias (mathlm) de Mathematica 4.0 y 4.1 permite que atacantes remotos pasen el control de acceso (especificado por el argumento -restrict) y roben una licencia por medio de una petición cliente que incluye el nombre de una máquina que tiene derecho a la licencia. | |
| Modificada | Alta (7.5) | 1.2% | — | Bell Communications Research S KEY | 2/9/2001 | 16/6/2026 | keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo. | |
| Modificada | Media (5) | 1.6% | — | Wolfram Research Mathematica | 30/7/2001 | 16/6/2026 | The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests. | |
| Modificada | Media (5) | 1.7% | — | Inktomi Search Software | 11/12/2000 | 16/6/2026 | Search engine in Ultraseek 3.1 and 3.1.10 (aka Inktomi Search) allows remote attackers to cause a denial of service via a malformed URL. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | SGI InfosearchSGI Irix | 1/3/2000 | 16/6/2026 | SGI InfoSearch CGI program infosrch.cgi allows remote attackers to execute commands via shell metacharacters. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Altavista Search Intranet | 29/12/1999 | 16/6/2026 | AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cgi CGI program. | |
| Modificada | Baja (2.6) | 1.5% | — | Disney GO Express Search | 12/12/1999 | 16/6/2026 | The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system. | |
| Modificada | Media (5) | 1.2% | — | CCS Network Hyperseek Search Engine | 19/2/1999 | 16/6/2026 | Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter. |