Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
–

1170 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.3%—Annuaire Directory3/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in inscription.php in Annuaire (Directory) 1.0 allows remote attackers to inject arbitrary web script or HTML via the Comment Field (COMMENTAIRE parameter).
ModificadaMedia (5)2.1%—Annuaire Directory3/4/200616/6/2026
Annuaire (Directory) 1.0 allows remote attackers to obtain sensitive information via a direct request to include/lang-en.php, which reveals the full installation path.
ModificadaAlta (7.5)1.8%—Articlesone 99articles Directory22/3/200616/6/2026
PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the page parameter.
ModificadaMedia (4.3)1.2%—Boonex Barracuda Directory22/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest Category module. NOTE: the provenance of this information is unknown; portions of the details are obtained from third…
ModificadaMedia (5)9.7%💥 ExploitIBM Tivoli Directory Server15/2/200616/6/2026
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request, as demonstrated by test 2532 in the ProtoVer Sample LDAP test suite.
ModificadaMedia (5)9.9%💥 ExploitSUN Java System Directory Server13/2/200616/6/2026
LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite.
ModificadaAlta (7.5)2.0%—Pdfdirectory19/1/200616/6/2026
Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php,…
ModificadaAlta (7.5)1.1%—Pdfdirectory19/1/200616/6/2026
PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities.
ModificadaMedia (5)1.6%—IDV Directory Viewer5/1/200616/6/2026
Vulnerabilidad de atravesamiento de directorios en index.php en IDV Directory Viewer anteriores a 2005.1 permite a atacantes remotos ver el contenido de directorios de su elección mediante un .. (punto punto) en el parámetro "dir".
ModificadaAlta (7.2)1.2%—Adobe CaptivateAdobe ContributeAdobe DirectorAdobe Dreamweaver+531/12/200516/6/2026
Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.
ModificadaAlta (10)19%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+3031/12/200516/6/2026
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
ModificadaMedia (4.3)1.2%—MR. CGI GUY Amazon Search Directory6/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly the search parameter.
ModificadaAlta (7.5)1.2%—Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+73/12/200516/6/2026
SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote…
AnalizadaAlta (7.5)4.1%💥 ExploitSoftbizscripts WEB Hosting Directory Script26/11/200516/6/2026
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an…
ModificadaMedia (5.8)0.92%—IBM Tivoli Directory Server16/11/200516/6/2026
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.
ModificadaMedia (4.3)2.0%💥 ExploitChipmunk Scripts Chipmunk Directory6/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter.
ModificadaAlta (7.5)1.6%—Techno Dreams WEB Directory30/10/200516/6/2026
SQL injection vulnerability in Techno Dreams Web Directory script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.
ModificadaAlta (7.5)3.1%—SUN Java System Directory Proxy ServerSUN Java System Directory ServerSUN ONE Administration ServerSUN ONE Directory Server20/10/200516/6/2026
Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2…
ModificadaAlta (7.5)55%💥 ExploitNovell Edirectory12/8/200516/6/2026
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.
ModificadaBaja (2.1)0.35%—Mcdata Intrepid 6064 Director SwitchMcdata Intrepid 6140 Director SwitchMcdata Sphereon 4300 Fabric SwitchMcdata Sphereon 4500 Fabric Switch7/8/200516/6/2026
Vulnerabilidad desconocida en conmutadores y directores Sun McData 4300, 4500, 6064 y 6140 anteriores a E/OS 6.0.0 pueden permitir a atacantes causar una denegación de servicio (conectividad de acceso al array perdida) mediante un tormenta de multidifusión (broadcasten la red.
ModificadaMedia (5)1.6%—Novell Edirectory12/6/200516/6/2026
Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.
ModificadaMedia (4.3)1.6%💥 ExploitAccomplishtechnology Phpmydirectory2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) page, or (3) subsubcat parameter.
ModificadaMedia (5)1.5%—Anaconda Partners Foundation Directory2/5/200516/6/2026
Directory traversal vulnerability in apexec.pl for Anaconda Foundation Directory allows remote attackers to read arbitrary files via hex-encoded null characters (%00) in the middle of ".." sequences in the template parameter.
ModificadaAlta (10)2.6%—Altiris Deployment Server Extension FOR IBM Director31/12/200416/6/2026
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.
ModificadaAlta (10)8.9%—Netscape Directory Server31/12/200416/6/2026
Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code.
Orbitaley — Vulnerabilidades