Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.3% | — | Phpgroupware | 24/12/2009 | 16/6/2026 | SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the passwd parameter to login.php. | |
| Modificada | Media (4.3) | 1.4% | — | Horde Application FrameworkHorde Groupware | 21/12/2009 | 16/6/2026 | Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 does not properly handle data: URIs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via data:text/html values for the HREF… | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Horde Application FrameworkHorde Groupware | 21/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2)… | |
| Modificada | Media (4.3) | 2.3% | — | Horde Application FrameworkHorde GroupwareHorde Groupware | 17/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; allow remote attackers to inject arbitrary web script or HTML via the (1)… | |
| Modificada | Media (4.3) | 2.3% | — | Horde Application FrameworkHorde Groupware | 17/9/2009 | 16/6/2026 | The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to… | |
| Modificada | Alta (10) | 2.7% | — | Horde GroupwareHorde Groupware Webmail EditionHorde Kronolith H3Horde Mnemo H3+1 | 13/9/2009 | 16/6/2026 | Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 before 2.2-RC2; Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 does not validate ownership when… | |
| Modificada | Alta (10) | 2.2% | — | Horde GroupwareHorde Groupware Webmail EditionHordeHorde Kronolith H3+3 | 13/9/2009 | 16/6/2026 | Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and 2.2 before 2.2-RC2; Horde… | |
| Modificada | Alta (7.5) | 1.4% | — | Hitachi Groupmax Groupware ServerHitachi Groupmax Scheduler Server SETHitachi Groupmax Server SET | 11/9/2009 | 16/6/2026 | Unspecified vulnerability in Hitachi Groupmax Groupware Server 07-00 through 07-50-/A, Groupmax Server Set 03-00 through 06-52, Groupware Server Set 03-00 through 06-52, and Scheduler Server Set 03-00 through 06-52 has unknown impact and attack vectors related to invalid access rights. | |
| Modificada | Alta (7.5) | 1.5% | — | Tikiwiki Cms/groupware | 24/8/2009 | 16/6/2026 | TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 3.9% | — | DAN Cahill Nulllogic Groupware | 7/7/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, might allow remote attackers to execute arbitrary code via input to the (1) POP3, (2) SMTP, or (3) web component that triggers a long SQL query. | |
| Modificada | Media (4) | 1.1% | — | DAN Cahill Nulllogic Groupware | 7/7/2009 | 16/6/2026 | The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (application crash) by specifying (1) an empty string or (2) a non-numeric string when selecting a forum, related to the fmessagelist function. | |
| Modificada | Alta (7.5) | 1.1% | — | Nulllogic Groupware | 7/7/2009 | 16/6/2026 | SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Tikiwiki Cms/groupware | 1/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php. | |
| Modificada | Media (6.4) | 46% | 💥 Exploit | Debian HordeDebian Horde Groupware | 17/3/2009 | 16/6/2026 | Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name. | |
| Modificada | Media (4.3) | 2.0% | — | Debian HordeDebian Horde Groupware | 17/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the tag cloud search script (horde/services/portal/cloud_search.php) in Horde before 3.2.4 and 3.3.3, and Horde Groupware before 1.1.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Bitdefender AntivirusBitdefenderBullguard Internet SecuritySoftware602 Groupware Server | 10/12/2008 | 16/6/2026 | Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted… | |
| Modificada | Media (5) | 1.3% | — | Tikiwiki Cms/groupware | 3/12/2008 | 16/6/2026 | Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653. | |
| Modificada | Media (5) | 1.3% | — | Tikiwiki Cms/groupware | 3/12/2008 | 16/6/2026 | Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653. | |
| Modificada | Media (4) | 0.97% | — | Kolab Groupware Server | 22/9/2008 | 16/6/2026 | admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwords by reading the ssl_access_log file or the referer string. | |
| Modificada | Alta (9) | 1.0% | — | Horde Groupware Webmail Edition | 13/8/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Horde Groupware Webmail before Edition 1.1.1 (final) have unknown impact and attack vectors related to "unescaped output," possibly cross-site scripting (XSS), in the (1) object browser and (2) contact view. | |
| Modificada | Media (5) | 1.0% | — | Tikiwiki Cms/groupware | 13/8/2008 | 16/6/2026 | Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors. | |
| Modificada | Alta (10) | 1.6% | — | Tikiwiki Cms/groupware | 13/8/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Horde GroupwareHorde Groupware Webmail EditionHorde Kronolith | 19/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Horde Groupware, Groupware Webmail Edition, and Kronolith allow remote attackers to inject arbitrary web script or HTML via the timestamp parameter to (1) week.php, (2) workweek.php, and (3) day.php; and (4) the horde parameter in the PATH_INFO to the default URI.… | |
| Modificada | Alta (10) | 1.6% | — | Egroupware | 30/4/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root. | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Horde GroupwareHorde Groupware Webmail Edition | 27/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and Groupware 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the url parameter. |