Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
1104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.8% | — | Drupal Userreview Module | 15/9/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la revisión de usuario de Drupal 4.7 anterior a 1.19 (12/09/2006) permite a a atacantes remotos inyectar secuencias de comandos web de su elección o HTML a través de vectores no especificados. | |
| Modificada | Media (6.8) | 3.2% | — | UserminWebmin | 5/9/2006 | 16/6/2026 | Webmin anterior a 1.296 y Usermin anterior a 1.226 no dirigidas adecuadamente una URL con un caracter nulo ("%00"), lo cual permite a un atacante remoto dirigir una secuencia de comandos de sitios cruzados (XSS), leer el código fuente del programa CGI, lista de directorios, y posiblemente ejecutar programas. | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | User Home Pages | 5/8/2006 | 16/6/2026 | Múltiples vulnerabilidades PHP de inclusión remota de archivo en (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, y (7) uninstall.uhp.php, en el componente UHP (User Home Pages) 0.5 (también conocido como com_uhp) para Mambo o Joomla,… | |
| Modificada | Media (5) | 79% | 💥 Exploit | UserminWebmin | 6/7/2006 | 16/6/2026 | Las aplicaciones Webmin antes de su versión 1.290 y Usermin antes de la 1.220 llaman a la función simplify_path antes de decodificar HTML, lo que permite a atacantes remotos leer ficheros arbitrarios, como se ha demostrado utilizando secuencias "..% 01", evitando de esta manera la supresión del nombre de fichero de… | |
| Modificada | Media (5.1) | 3.3% | 💥 Exploit | Ezusermanager | 17/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the ezUserManager_Path parameter to ezusermanager_pwd_forgott.php, possibly due to an issue in ezusermanager_core.inc.php. | |
| Modificada | Media (4.3) | 1.3% | — | Sloughflash Sf-users | 4/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element. | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco User Registration ToolCisco Wireless LAN Solution EngineCiscoworks 2000 Service Management SolutionCisco Hosting Solution Engine+1 | 21/4/2006 | 16/6/2026 | Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell… | |
| Modificada | Baja (2.6) | 1.2% | — | Userland Manila | 20/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila allow remote attackers to inject arbitrary web script or HTML (1) via the referer parameter in sendMail, and via attributes of (2) the A element and certain other HTML elements in web pages edited with the editInBrowser module. NOTE: the… | |
| Modificada | Media (6.8) | 1.6% | — | Userland Manila | 13/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in UserLand Manila 9.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the mode parameter in msgReader$1 and (2) the end of the URI in viewDepartment$. | |
| Modificada | Alta (10) | 1.7% | — | Intensive Point Iuser Ecommerce | 24/2/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Intensive Point iUser Ecommerce before 2.2 have unspecified vectors and impact, as addressed by "Urgent secure fixes". NOTE: this might be a duplicate of CVE-2006-0854, but the vendor announcement for this issue (from January 8, 2005) is too vague to be sure, and CVE-2006-0854… | |
| Modificada | Media (6.4) | 4.0% | 💥 Exploit | Pear Liveuser | 23/2/2006 | 16/6/2026 | Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot… | |
| Modificada | Alta (7.5) | 2.1% | — | Intensive Point Iuser Ecommerce | 23/2/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initialized before being used. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Subzane Szusermgnt | 1/2/2006 | 16/6/2026 | SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 4.1% | — | UserminWebmin | 22/9/2005 | 16/6/2026 | miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return). | |
| Modificada | Alta (7.5) | 1.6% | — | Mark D. Roth PAM PER User | 16/9/2005 | 16/6/2026 | pam_per_user before 0.4 does not verify if the user name changes between authentication attempts and uses the same subrequest handle, which allows remote attackers or local users to login as other users by using certain applications that allow the username to be changed during authentication, such as /bin/login. | |
| Modificada | Alta (10) | 1.8% | — | UserminWebmin | 2/5/2005 | 16/6/2026 | Unknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unknown impact. | |
| Modificada | Alta (7.5) | 1.2% | — | Access User Class | 8/4/2005 | 16/6/2026 | Vulnerability in Access_user Class before 1.75 allows local users to gain access as other users via the password "new". | |
| Modificada | Alta (7.5) | 3.6% | — | UserminWebmin | 31/12/2004 | 16/6/2026 | The web mail functionality in Usermin 1.x and Webmin 1.x allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail message. | |
| Modificada | Baja (2.1) | 0.36% | — | UserminWebminMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 20/10/2004 | 16/6/2026 | El script maketemp.pl en Usermin 1.070 y 1.080 permite a usuarios locales sobreescribir ficheros de su elección durante la instalación mediante un ataque de enlaces simbólicos en el directorio /tmp/.usermin | |
| Modificada | Media (5) | 2.1% | — | UserminWebminDebian Linux | 6/8/2004 | 16/6/2026 | La funcionalidad lockout en (1)Webmin 1.140 y (2) Usermin 1.070 no process ciertas cadenas de caractéreis, lo que permite a atacanetes remotos conducir un ataque de fuerza bruta para averiguar IDs de usuario y contraseñas. | |
| Modificada | Media (6.8) | 1.4% | — | Usermin | 6/8/2004 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el módulo de correo web de Usermin 1.070 permite a atacantes remotos insertar HTML y scrpit de su elección mediante mensajes de correo electrónico. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Engardelinux Guardian Digital WebtoolUserminWebmin | 3/3/2003 | 16/6/2026 | miniserv.pl en Webmin anterior a 1.070 y Usermin antes de 1.000 no maneja adecuadamente metacaractéres como avance de línea y retorno de carro (CRLF) en cadenas codificadas en Base-64 durante la autenticación básica, lo que permite a atacantes remotos suplantar un ID de sesión y ganar privilegios de root. | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | User-mode Linux | 31/12/2002 | 16/6/2026 | User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.9% | — | UserminWebmin | 12/8/2002 | 16/6/2026 | Webmin 0.96 y Usermin 0.90 con tiempo de espera para contraseñas habilitado, permite a atacantes locales y posiblemente a remotos, evitar la autenticación y obtener privilegios mediante ciertos caracteres de control en la información de autenticación, que podría forzar a Webmin o Usermin a aceptar combinaciones… | |
| Modificada | Alta (7.5) | 1.7% | — | UserminWebmin | 12/8/2002 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en la página de autenticación de: Webmin 0.96 Usermin 0.90 que permite a atacantes remotos la inserción de código en una página de error y posiblemente el robo de cookies. |