Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | — | Tornado Knowledge Retrieval System | 28/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado Knowledge Retrieval System 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the p parameter in a root action. | |
| Modificada | Alta (7.5) | 0.97% | — | Knowledgebase-script Phpkb Knowledge Base Software | 14/11/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909. | |
| Modificada | Media (6.8) | 1.9% | — | WSN ForumWSN GalleryWSN Knowledge BaseWSN Links | 8/8/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3) Knowledge Base (WSNKB) 4.1.36 and earlier, (4) Links 4.1.44 and earlier, and possibly (5) Classifieds before 4.1.30 allows remote attackers to include and execute arbitrary local files via a .. (dot… | |
| Modificada | Media (4.3) | 2.3% | — | Intranet Knowledgebase | 29/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter in a getpasswd action to register.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Intranet Knowledgebase | 29/7/2008 | 16/6/2026 | SQL injection vulnerability in register.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 0.98% | — | Chadha Software Technologies Phpkb Knowledge Base | 22/4/2008 | 16/6/2026 | SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Myknowledgequest Knowledgequest | 11/4/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) kqid parameter to (a) articletext.php and (b) articletextonly.php and the (2) username parameter to (c) logincheck.php. | |
| Modificada | Alta (7.5) | 6.9% | — | Myknowledgequest Knowledgequest | 11/4/2008 | 16/6/2026 | KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin accounts. | |
| Modificada | Media (4.3) | 1.2% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 10/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Dokeos 1.8.4 before SP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 10/3/2008 | 16/6/2026 | Unspecified vulnerability in Dokeos 1.8.4 before SP3 allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Dokeos Open Source Learning AND Knowledge ManagementDokeos Open Source Learning AND Knowledge Management Tool | 28/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the origin parameter to work/work.php in a display_upload_form action, or the forum parameter to (2) forum/viewforum.php or (3) forum/viewthread.php. | |
| Modificada | Media (4.3) | 1.3% | — | Knowledgetree Open Source | 9/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 30/5/2007 | 16/6/2026 | SQL injection vulnerability in tracking/courseLog.php in Dokeos 1.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the scormcontopen parameter. | |
| Modificada | Alta (10) | 2.7% | — | Knowledgetree Document Management | 24/5/2007 | 16/6/2026 | KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended authorization check. | |
| Modificada | Alta (10) | 1.6% | — | Peanutkb Peanut Knowledge Base | 21/2/2007 | 16/6/2026 | Unspecified vulnerability in Peanut Knowledge Base (PeanutKB) 0.0.3 and earlier has unknown impact and attack vectors. | |
| Modificada | Media (6.8) | 1.6% | — | Fixit Knowledge Solutions Idms PRO Image Gallery | 1/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in Fixit iDMS Pro Image Gallery allows remote attackers to inject arbitrary web script or HTML via a search field (txtsearchtext parameter). | |
| Modificada | Alta (7.5) | 1.1% | — | Fixit Knowledge Solutions Idms PRO Image Gallery | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp. | |
| Modificada | Alta (7.5) | 3.2% | — | Activecampaign Knowledgebuilder | 15/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the visEdit_root parameter, a different vector than CVE-2003-1131. | |
| Modificada | Media (4.3) | 1.3% | — | Timothy Claason Knowledgebank | 25/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Timothy Claason KnowledgeBank 1.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) index.php, (2) addknowledge.php, and (3) addscreenshot.php. | |
| Modificada | Media (5.1) | 10% | — | ClarolineDokeos Open Source Learning AND Knowledge Management Tool | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter. | |
| Modificada | Media (4.3) | 1.8% | — | JAM Warehouse Knowledgetree Open Source | 7/6/2006 | 16/6/2026 | view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS. | |
| Modificada | Media (4.3) | 1.3% | — | Knowledgetree | 7/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree Open Source 3.0.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) fDocumentId parameter in view.php and the (2) fSearchableText parameter in /search/simpleSearch.php. | |
| Modificada | Media (4.6) | 0.33% | — | Knowledgetree | 18/5/2006 | 16/6/2026 | The Debian package of knowledgetree 2.0.7 creates environment.php with world-readable permissions, which allows local users to obtain sensitive information such as the username and password for the KnowledgeTree database. | |
| Modificada | Media (5.1) | 4.1% | — | Dokeos Open Source Learning AND Knowledge Management Tool | 10/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Chadha Software Technologies Phpkb Knowledge Base | 4/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in PHPKB Knowledge Base allows remote attackers to inject arbitrary web script or HTML via the searchkeyword parameter. NOTE: the issue was originally disputed by the vendor, but on 20060519, the vendor notified CVE that "We have fixed all the mentioned issues and… |