Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.7% | — | Marcus Schafer KiwiNovell Suse Studio Onsite | 23/8/2011 | 16/6/2026 | Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename in the list of testdrive modified files. | |
| Modificada | Alta (7.5) | 2.7% | — | Marcus Schafer KiwiNovell Suse Studio Onsite | 23/8/2011 | 16/6/2026 | Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to execute arbitrary code via a crafted filename for a custom RPM. | |
| Modificada | Media (4.3) | 1.2% | — | Marcus Schafer KiwiNovell Suse Studio Onsite | 23/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an RPM info display. | |
| Modificada | Media (4.3) | 1.2% | — | Marcus Schafer KiwiNovell Suse Studio Onsite | 23/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing. | |
| Modificada | Alta (9.3) | 1.4% | — | Marcus Schafer KiwiNovell Suse Studio Onsite | 23/8/2011 | 16/6/2026 | Unspecified vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to have an unknown impact via a crafted directory pathname that is inserted into config.sh. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Marcusg MG User Fotoalbum Panel | 27/4/2011 | 16/6/2026 | SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user_fotoalbum_panel) module 1.0.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the album_id parameter. | |
| Modificada | Alta (9.3) | 5.1% | — | March-hare CVS SuiteMarch-hare Cvsnt | 15/9/2010 | 16/6/2026 | perms.cpp in March Hare Software CVSNT 2.0.58, 2.5.01, 2.5.02, 2.5.03 before build 3736, 2.5.04 before build 2862; CVS Suite 2.5.03, 2008 before build 3736, and 2009 before 3729 allows remote attackers to bypass the permissions check, modify arbitrary modules and directories within CVSROOT, and execute arbitrary code… | |
| Modificada | Alta (7.5) | 1.5% | — | Marcus Krause T3sec Saltedpw | 19/3/2010 | 16/6/2026 | The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Marc-andre Lanciault Smartmedia | 20/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter. | |
| Modificada | Media (6.5) | 2.0% | 💥 Exploit | Marcin Manek D.net CMS | 1/10/2009 | 16/6/2026 | Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the type parameter. | |
| Modificada | Media (6.5) | 0.84% | 💥 Exploit | Marcin Manek D.net CMS | 1/10/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php. | |
| Modificada | Media (6.5) | 4.8% | 💥 Exploit | Infireal Mxcamarchive | 12/8/2009 | 16/6/2026 | Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Infireal Mxcamarchive | 12/8/2009 | 16/6/2026 | mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain configuration details and passwords via a direct request for archive/config.ini. | |
| Modificada | Alta (7.5) | 1.4% | — | Marc Ingram Services | 6/8/2009 | 16/6/2026 | Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request. | |
| Modificada | Media (6.5) | 1.1% | — | Marc Ingram Services | 6/8/2009 | 16/6/2026 | Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges. | |
| Modificada | Alta (7.5) | 1.4% | — | Marc Ingram Services | 6/8/2009 | 16/6/2026 | Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges. | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Marcelo Costa Fileserver | 20/7/2009 | 16/6/2026 | Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Marc Melvin A+ PHP Scripts News Management System | 8/4/2009 | 16/6/2026 | A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1. | |
| Modificada | Media (6.9) | 0.34% | — | Marc Gloor Screenie | 8/12/2008 | 16/6/2026 | screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file. | |
| Modificada | Media (6.9) | 0.40% | — | Marco D'itri Ppp-udeb | 8/12/2008 | 16/6/2026 | ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp temporary file. | |
| Modificada | Media (6.9) | 0.38% | — | Marco D'itri PPP | 8/12/2008 | 16/6/2026 | The postinst script in ppp 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/probe-finished or (2) /tmp/ppp-errors temporary file. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Marcello Brandao Yogurt Social Network Module | 13/8/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Yogurt Social Network module 3.2 rc1 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the uid parameter to (1) friends.php, (2) seutubo.php, (3) album.php, (4) scrapbook.php, (5) index.php, or (6) tribes.php; or (7) the description… | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Marcioforum Mforum | 16/7/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) City, (2) Interest, (3) Email, (4) Icq, (5) msn, or (6) Yahoo Messenger field in an edit_profile action. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | March Networks 3204 DVR | 4/1/2008 | 16/6/2026 | March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz. | |
| Modificada | Alta (7.8) | 1.7% | — | Michal Marcinkowski Soldat Dedicated ServerMichal Marcinkowski Soldat Game Server | 25/8/2007 | 16/6/2026 | Soldat game server 1.4.2 and earlier, and dedicated server 2.6.2 and earlier, allows remote attackers to cause a denial of service (client lockout) via a series of UDP join packets from a spoofed IP address, which triggers temporary blacklisting of this IP address. |