Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.7% | — | Ikiwiki | 31/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI. | |
| Modificada | Alta (7.5) | 1.7% | — | Tikiwiki Cms/groupware | 27/3/2010 | 16/6/2026 | The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Tikiwiki Cms/groupware | 27/3/2010 | 16/6/2026 | The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse. | |
| Modificada | Alta (7.5) | 1.3% | — | Tikiwiki Cms/groupware | 27/3/2010 | 16/6/2026 | SQL injection vulnerability in the _find function in searchlib.php in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to execute arbitrary SQL commands via the $searchDate variable. | |
| Modificada | Alta (7.5) | 1.4% | — | Tikiwiki Cms/groupware | 27/3/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in TikiWiki CMS/Groupware 4.x before 4.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, probably related to (1) tiki-searchindex.php and (2) tiki-searchresults.php. | |
| Modificada | Media (5) | 1.8% | — | Ikiwiki | 31/8/2009 | 16/6/2026 | Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands. | |
| Modificada | Alta (7.5) | 1.5% | — | Tikiwiki Cms/groupware | 24/8/2009 | 16/6/2026 | TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Internet Explorer "Remember Me" feature. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | Ishii Pukiwikimod | 22/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the XOOPS MANIAC PukiWikiMod module 1.6.6.2 and earlier for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Tikiwiki Cms/groupware | 1/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php. | |
| Modificada | Media (5) | 1.3% | — | Tikiwiki Cms/groupware | 3/12/2008 | 16/6/2026 | Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653. | |
| Modificada | Media (5) | 1.3% | — | Tikiwiki Cms/groupware | 3/12/2008 | 16/6/2026 | Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653. | |
| Modificada | Media (5) | 1.0% | — | Tikiwiki Cms/groupware | 13/8/2008 | 16/6/2026 | Unspecified vulnerability in TikiWiki CMS/Groupware before 2.0 allows attackers to obtain "path and PHP configuration" via unknown vectors. | |
| Modificada | Alta (10) | 1.6% | — | Tikiwiki Cms/groupware | 13/8/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in TikiWiki CMS/Groupware before 2.0 have unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Mindtouch Dekiwiki | 25/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in MindTouch DekiWiki before 8.05.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.6% | — | Ikiwiki | 3/6/2008 | 16/6/2026 | Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence. | |
| Modificada | Media (4.3) | 0.64% | — | Ikiwiki | 21/4/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms. | |
| Modificada | Media (4.3) | 1.1% | — | Tikiwiki Cms/groupware | 27/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-edit_article.php in TikiWiki before 1.9.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Ikiwiki | 19/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the meta plugin in Ikiwiki before 1.1.47 allows remote attackers to inject arbitrary web script or HTML via meta tags. | |
| Modificada | Media (4.3) | 1.1% | — | Ikiwiki | 19/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the htmlscrubber in Ikiwiki before 1.1.46 allows remote attackers to inject arbitrary web script or HTML via title contents. | |
| Modificada | Alta (10) | 1.9% | — | Tikiwiki Cms/groupware | 27/12/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in TikiWiki before 1.9.9 have unknown impact and attack vectors involving (1) tiki-edit_css.php, (2) tiki-list_games.php, or (3) tiki-g-admin_shared_source.php. | |
| Modificada | Media (4.3) | 1.6% | — | Tikiwiki Cms/groupware | 27/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-special_chars.php in TikiWiki before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via the area_name parameter. | |
| Modificada | Media (5) | 9.3% | 💥 Exploit | Tikiwiki Cms/groupware | 27/12/2007 | 16/6/2026 | Directory traversal vulnerability in tiki-listmovies.php in TikiWiki before 1.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) and modified filename in the movie parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Tikiwiki Cms/groupware | 26/10/2007 | 16/6/2026 | Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows remote attackers to execute arbitrary code by using variable functions and variable variables to write variables whose names match the whitelist, a different vulnerability than CVE-2007-5423. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Tikiwiki Cms/groupware | 26/10/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to include and execute arbitrary files via an absolute pathname in (1) error_handler_file and (2) local_php parameters to (a) tiki-index.php, or (3) encoded "..%2F" sequences in the imp_language parameter to… | |
| Modificada | Media (4.3) | 0.89% | — | Tikiwiki Cms/groupware | 26/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki pages, and (3) the local_php parameter to db/tiki-db.php. |