Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.0% | — | Really Simple Caldav Store | 14/11/2007 | 16/6/2026 | Unspecified vulnerability in Really Simple CalDAV Store (RSCDS) before 0.9.0 allows attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Scallywag.org Scallywag | 31/5/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in Scallywag 2005-04-25 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin_name parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/, a different vector than CVE-2007-2900. NOTE: the provenance of… | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Scallywag.org Scallywag | 30/5/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to template.php in (1) skin/dark/, (2) skin/gold/, or (3) skin/original/. | |
| Modificada | Alta (7.5) | 9.9% | 💥 Exploit | Really Simple PHP AND Ajax | 12/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) __IncludeFilePHPClass, (2) __ClassPath, and (3) __class parameters to (a) rspa/framework/Controller_v5.php, and (b)… | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Really Simple PHP AND Ajax | 3/4/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the __class parameter to (1) Controller_v4.php or (2) Controller_v5.php. | |
| Modificada | Alta (7.5) | 3.4% | — | Techland Xpand Rally | 2/5/2005 | 16/6/2026 | Format string vulnerability in Xpand Rally 1.1.0.0 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a message. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Techland Xpand Rally | 2/5/2005 | 16/6/2026 | Xpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet with large values that are not properly handled in certain malloc or memcpy operations. | |
| Modificada | Media (5) | 1.5% | — | Arsc Really Simple Chat | 12/8/2002 | 16/6/2026 | home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message. |