Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 9 respecto a la semana anterior
Críticas / altas1289▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

1294 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Interactivephp Fusionbb13/6/200516/6/2026
Multiple SQL injection vulnerabilities in InteractivePHP FusionBB .11 Beta and earlier allow remote attackers to execute arbitrary SQL commands via (1) the username, which is not properly handled by the insertUser function, or (2) the bb_session_id value in a cookie.
ModificadaAlta (10)7.0%—Fusion SBX16/5/200516/6/2026
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.
ModificadaMedia (4.3)1.2%—Macromedia Coldfusion10/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.
ModificadaMedia (5)1.7%—Macromedia Coldfusion2/5/200516/6/2026
ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.
ModificadaMedia (4.3)1.7%💥 ExploitPHP Fusion2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.
ModificadaMedia (5)2.8%💥 ExploitPHP Fusion2/5/200516/6/2026
viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter.
ModificadaMedia (4.3)1.2%—PHP Fusion6/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.
ModificadaMedia (5)1.6%—Macromedia Coldfusion31/12/200416/6/2026
ColdFusion MX 6.1 and 6.1 J2EE allows remote attackers to cause a denial of service via an HTTP request containing a large number of form fields.
ModificadaAlta (7.2)0.35%—Macromedia Coldfusion31/12/200416/6/2026
Macromedia ColdFusion MX 6.0 and 6.1 application server, when running with the CreateObject function or CFOBJECT tag enabled, allows local users to conduct unauthorized activities and obtain administrative passwords by creating CFML scripts that use CreateObject or CFOBJECT.
ModificadaMedia (5)3.2%💥 ExploitMacromedia Coldfusion31/12/200416/6/2026
Macromedia ColdFusion MX before 6.1 does not restrict the size of error messages, which allows remote attackers to cause a denial of service (memory consumption and crash) by sending repeated GET or POST requests that trigger error messages that use long strings of data.
ModificadaMedia (5)1.2%—PHP Fusion31/12/200416/6/2026
The (1) updateuser.php and (2) forums_prune.php scripts in PHP-Fusion 4.00 allow remote attackers to obtain sensitive information via a direct HTTP request, which reveals the installation path in an error message.
ModificadaAlta (7.5)3.4%—Hitachi Cosminexus EnterpriseHitachi Cosminexus ServerMacromedia ColdfusionMacromedia Jrun31/12/200416/6/2026
JRun 4.0 does not properly generate and handle the JSESSIONID, which allows remote attackers to perform a session fixation attack and hijack a user's HTTP session.
ModificadaAlta (7.5)1.2%—PHP Fusion31/12/200416/6/2026
SQL injection vulnerability in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the rowstart parameter to (1) index.php or (2) members.php, or (3) the comment_id parameter to comments.php.
ModificadaMedia (5.5)0.67%—Macromedia Coldfusion31/12/200416/6/2026
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
ModificadaMedia (4.3)1.2%—PHP Fusion31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in PHP-Fusion 4.01 allows remote attackers to inject arbitrary web script or HTML via the (1) Submit News, (2) Submit Link or (3) Submit Article field.
ModificadaAlta (10)7.1%—Macromedia ColdfusionMacromedia Jrun23/12/200416/6/2026
Desbordamiento de búfer en la función WriteToLog de los conectores web JRun 3.0 a 4.0, como mod_jrun y mod_jrun20 para Apache con registro verboso activado, permite a atacantes remotos ejecutar código de su elección mediante una una cabecera HTTP Content-Type larga u otros campos.
ModificadaMedia (5)4.1%—Hitachi Cosminexus EnterpriseHitachi Cosminexus ServerMacromedia ColdfusionMacromedia Jrun5/10/200416/6/2026
The Microsoft IIS Connector in JRun 4.0 and Macromedia ColdFusion MX 6.0, 6.1, and 6.1 J2EE allows remote attackers to bypass authentication and view source files, such as .asp, .pl, and .php files, via an HTTP request that ends in ";.cfm".
ModificadaAlta (7.5)6.9%💥 ExploitPHP Fusion18/8/200416/6/2026
The ReadMe First.txt file in PHP-Fusion 4.0 instructs users to set the permissions on the fusion_admin/db_backups directory to world read/write/execute (777), which allows remote attackers to download or view database backups, which have easily guessable filenames and contain the administrator username and password.
ModificadaAlta (8.8)2.0%💥 ExploitFusionphp Fusion News30/7/200416/6/2026
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.
ModificadaBaja (2.6)1.5%—Macromedia Coldfusion1/6/200416/6/2026
The HTML form upload capability in ColdFusion MX 6.1 does not reclaim disk space if an upload is interrupted, which allows remote attackers to cause a denial of service (disk consumption) by repeatedly uploading files and interrupting the uploads before they finish.
ModificadaMedia (5)1.6%—Macromedia ColdfusionMacromedia JrunSUN ONE Application Server15/3/200416/6/2026
Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).
ModificadaMedia (5)6.2%💥 ExploitMacromedia ColdfusionMacromedia Coldfusion Professional31/12/200316/6/2026
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows remote attackers to obtain the full path of the web server via a direct request to CFIDE/probe.cfm, which leaks the path in an error message.
ModificadaMedia (4.3)24%💥 ExploitMacromedia ColdfusionMicrosoft Internet Information ServicesMicrosoft Windows 200031/12/200216/6/2026
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
ModificadaMedia (5)1.8%—Macromedia ColdfusionMacromedia Coldfusion Professional31/12/200216/6/2026
Buffer overflow in jrun.dll in ColdFusion MX, when used with IIS 4 or 5, allows remote attackers to cause a denial of service in IIS via (1) a long template file name or (2) a long HTTP header.
ModificadaAlta (7.5)2.0%—Macromedia Coldfusion29/11/200216/6/2026
Desbordamiento de búfer en el mecanismo de manejo de errores del manejador de IIS ISAPI en Macromedia ColdFusion 6.0 permite a atacantes remotos ejecutar código arbitrario mediante una petición HTTP GET con un nombre de fichero .cfm largo.