Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
1237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Interspire Articlelive | 23/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter. | |
| Modificada | Alta (7.2) | 0.39% | — | Woodstone Servers Alive | 16/3/2005 | 16/6/2026 | Servers Alive 4.1 and 5.0, when running as a service, does not drop SYSTEM privileges before loading local manual under the help menu, which allows local users to gain privileges. | |
| Modificada | Media (5) | 3.2% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets. | |
| Modificada | Media (5) | 1.6% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded. | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Monolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions NO ONE Lives ForeverMonolith Productions Shogo | 31/12/2004 | 16/6/2026 | Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query. | |
| Modificada | Alta (7.5) | 1.5% | — | Alivesites Forum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in forum.asp in AliveSites Forums 2.0 allows remote attackers to execute arbitrary SQL commands via the forum_id parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Crafty Syntax Live Help | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Crafty Syntax Live Help (CSLH) before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the name field of a livehelp or chat session. | |
| Modificada | Media (4.3) | 1.4% | — | Ubertec Help Center Live | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php. | |
| Modificada | Media (5) | 1.5% | — | PHP Live | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in PHP Live! before 2.8.2, due to a "major security problem," allows remote attackers to include arbitrary files and directories via unspecified attack vectors. | |
| Modificada | Media (4.3) | 1.4% | — | Alivesites Forum | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AliveSites Forums 2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) forum_id, (2) method, or (3) forum_title parameters to post.asp, (4) the forum_title parameter to forum.asp, or (5) the id parameter to post.asp. | |
| Modificada | Media (6.4) | 1.5% | — | Ubertec Help Center Live | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) allows remote attackers to read local files and possibly execute PHP code via a URL in the SKIN_inner parameter to inc/skin.php. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Liveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Monolith Productions Contract JackMonolith Productions NO ONE Lives Forever 2Monolith Productions Tron | 31/12/2004 | 16/6/2026 | The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that… | |
| Modificada | Baja (2.1) | 1.9% | 💥 Exploit | Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+7 | 31/12/2004 | 16/6/2026 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. | |
| Modificada | Media (6.8) | 1.9% | — | Ubertec Help Center Live | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in UberTec Help Center Live (HCL) before 1.2.7 allows remote attackers to execute arbitrary PHP code via a URL in the HCL_path parameter to pipe.php. | |
| Modificada | Media (6.8) | 1.3% | — | Livejournal | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in LiveJournal 1.0 and 1.1 allows remote attackers to execute Javascript as other users via the stylesheet, which does not strip the semicolon or parentheses, as demonstrated using a background:url. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Emulive Server4 | 21/9/2004 | 16/6/2026 | EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to cause a denial of service (application crash) via a sequence of carriage returns sent to TCP port 66. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Emulive Server4 | 20/9/2004 | 16/6/2026 | EmuLive Server4 Commerce Edition Build 7560 allows remote attackers to bypass authentication for the remote administration feature via a URL that contains an extra leading / (slash). | |
| Modificada | Baja (2.1) | 0.47% | — | Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Admin-cd FOR FirewallSuse Linux Connectivity Server+13 | 6/8/2004 | 16/6/2026 | El controlador e1000 del kernel de Linux 2.4.26 y anteriores no inicializa la memoria antes de usarla, lo que permite a usuarios locales leer porciones de la memoria del kernel. NOTA: Este problema ha sido originalmente descrito incorrectamente por otras fuentes como un "desbordamiento de búfer". | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System WorksSymantec Windows Liveupdate | 3/2/2004 | 16/6/2026 | La funcionalidad gui para una sesión interactiva en ymantec LiveUpdate 1.70.x hasta la 1.90.x (usadas en Norton Internet Security 2001 hasta 2004, SystemWorks 2001 hasta 2004, y AntiVirus y Norton AntiVirus Pro 2001 hasta 2004, AntiVirus for Handhelds v3.0) permite que usuarios locales obtengan privilegios SYSTEM. | |
| Modificada | Alta (7.5) | 4.4% | — | Cisco Application AND Content Networking SoftwareCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content Distribution Manager 4670+5 | 5/1/2004 | 16/6/2026 | Desbordamiento de búfer en el módulo de autenticación de Cisco ACNS 4.x anteriores a 4.2.11, y 5.x anteriores a 5.0.5, permite a atacantes remotos ejecutar código arbitrario mediante una contraseña larga. | |
| Modificada | Media (4.3) | 0.97% | — | Silc Secure Internet Live Conferencing | 31/12/2003 | 16/6/2026 | Secure Internet Live Conferencing (SILC) 0.9.11 and 0.9.12 stores passwords and sessions in plaintext in memory, which could allow local users to obtain sensitive information. | |
| Modificada | Media (5) | 2.1% | — | Cgiscript.net Cslivesupport | 31/12/2002 | 16/6/2026 | csLiveSupport.cgi in CGIScript.net csLiveSupport allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. | |
| Modificada | Alta (7.5) | 1.6% | — | Deepmetrix Livestats | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in DeepMetrix LiveStats 5.03 through 6.2.1 allows remote attackers to execute arbitrary script as the LiveStats user via the (1) user-agent or (2) referrer, which are not filtered by the stats program. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content EngineCisco Enterprise Content Delivery Network Software+4 | 12/8/2002 | 16/6/2026 | The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP. |