Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
1170 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.3% | — | Annuaire Directory | 3/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inscription.php in Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary web script or HTML via the Comment Field (COMMENTAIRE parameter). | |
| Modificada | Media (5) | 2.1% | — | Annuaire Directory | 3/4/2006 | 16/6/2026 | Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path. | |
| Modificada | Alta (7.5) | 1.8% | — | Articlesone 99articles Directory | 22/3/2006 | 16/6/2026 | PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Boonex Barracuda Directory | 22/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest Category module. NOTE: the provenance of this information is unknown; portions of the details are obtained from third… | |
| Modificada | Media (5) | 9.7% | 💥 Exploit | IBM Tivoli Directory Server | 15/2/2006 | 16/6/2026 | IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite. | |
| Modificada | Media (5) | 9.9% | 💥 Exploit | SUN Java System Directory Server | 13/2/2006 | 16/6/2026 | LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite. | |
| Modificada | Alta (7.5) | 2.0% | — | Pdfdirectory | 19/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php,… | |
| Modificada | Alta (7.5) | 1.1% | — | Pdfdirectory | 19/1/2006 | 16/6/2026 | PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities. | |
| Modificada | Media (5) | 1.6% | — | IDV Directory Viewer | 5/1/2006 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en index.php en IDV Directory Viewer anteriores a 2005.1 permite a atacantes remotos ver el contenido de directorios de su elección mediante un .. (punto punto) en el parámetro "dir". | |
| Modificada | Alta (7.2) | 1.2% | — | Adobe CaptivateAdobe ContributeAdobe DirectorAdobe Dreamweaver+5 | 31/12/2005 | 16/6/2026 | Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (4.3) | 1.2% | — | MR. CGI GUY Amazon Search Directory | 6/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly the search parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 3/12/2005 | 16/6/2026 | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote… | |
| Analizada | Alta (7.5) | 4.1% | 💥 Exploit | Softbizscripts WEB Hosting Directory Script | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an… | |
| Modificada | Media (5.8) | 0.92% | — | IBM Tivoli Directory Server | 16/11/2005 | 16/6/2026 | slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Chipmunk Scripts Chipmunk Directory | 6/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Techno Dreams WEB Directory | 30/10/2005 | 16/6/2026 | SQL injection vulnerability in Techno Dreams Web Directory script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp. | |
| Modificada | Alta (7.5) | 3.1% | — | SUN Java System Directory Proxy ServerSUN Java System Directory ServerSUN ONE Administration ServerSUN ONE Directory Server | 20/10/2005 | 16/6/2026 | Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2… | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Novell Edirectory | 12/8/2005 | 16/6/2026 | Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors. | |
| Modificada | Baja (2.1) | 0.35% | — | Mcdata Intrepid 6064 Director SwitchMcdata Intrepid 6140 Director SwitchMcdata Sphereon 4300 Fabric SwitchMcdata Sphereon 4500 Fabric Switch | 7/8/2005 | 16/6/2026 | Vulnerabilidad desconocida en conmutadores y directores Sun McData 4300, 4500, 6064 y 6140 anteriores a E/OS 6.0.0 pueden permitir a atacantes causar una denegación de servicio (conectividad de acceso al array perdida) mediante un tormenta de multidifusión (broadcasten la red. | |
| Modificada | Media (5) | 1.6% | — | Novell Edirectory | 12/6/2005 | 16/6/2026 | Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Accomplishtechnology Phpmydirectory | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) page, or (3) subsubcat parameter. | |
| Modificada | Media (5) | 1.5% | — | Anaconda Partners Foundation Directory | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in apexec.pl for Anaconda Foundation Directory allows remote attackers to read arbitrary files via hex-encoded null characters (%00) in the middle of ".." sequences in the template parameter. | |
| Modificada | Alta (10) | 2.6% | — | Altiris Deployment Server Extension FOR IBM Director | 31/12/2004 | 16/6/2026 | AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access. | |
| Modificada | Alta (10) | 8.9% | — | Netscape Directory Server | 31/12/2004 | 16/6/2026 | Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code. |