Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2775▼ 14 respecto a la semana anterior
Críticas / altas1283▼ 250 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 205 respecto a la semana anterior
1274 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Nukescripts Nukesentinel | 1/10/2007 | 16/6/2026 | Vulnerabilidad de inyección SQL en la función abget_admin de includes/nukesentinel.php en NukeSentinel 2.5.12 permite a atacantes remotos ejecutar comandos SQL de su elección mediante datos codificados en base64 en una cookie de administrador. | |
| Modificada | Alta (7.5) | 1.1% | — | Nukescripts Nukesentinel | 1/10/2007 | 16/6/2026 | Vulnerabilidad de inyección SQL en la función is_god en includes/nukesentinel.php en NukeSentinel 2.5.11 permite a atacantes remotos ejecutar comandos SQL de su eleccióna través de datos códificados-base64 en una cookie admin, un vector diferente que CVE-2007-5125. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Nukescripts Nukesentinel | 16/3/2007 | 16/6/2026 | nukesentinel.php en NukeSentinel 2.5.06 y anteriores utilizar expresiones regulares un tanto permisivas en la validación de una dirección IP, lo cual permite a atacantes remotos ejecutar comandos SQL de su elección a través del cliente-IP en la cabcera HTTO, debido a un parche incompleto de la CVE-2007-1172. | |
| Modificada | Media (6.8) | 1.0% | — | Nukescripts Nukesentinel | 16/3/2007 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en NukeSentinel versiones anteriores a 2.5.06 permite a atacantes remotos inyectar scripts web o HTML de su elección mediante vectores sin especificar relativos a "filtros para https:// y http://". | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Nukescripts Nukesentinel | 2/3/2007 | 16/6/2026 | Una vulnerabilidad de inyección SQL en el archivo includes/nsbypass.php en NukeSentinel versiones 2.5.05, 2.5.11, y otras versiones anteriores a 2.5.12, permiten a los atacantes remotos ejecutar comandos SQL arbitrarios por medio de una cookie de administración. | |
| Modificada | Media (6.4) | 1.1% | 💥 Exploit | Nukescripts Nukesentinel | 2/3/2007 | 16/6/2026 | Vulnerabilidad de inyección SQL en nukesentinel.php en NukeSentinel 2.5.05, y posiblemente anteriores, permite a atacantes remotos ejecutar comandos SQL de su elección a través de la cabecera Client-IP HTTP, también conocido como "Exploit de acceso a archivo". | |
| Modificada | Media (5) | 1.8% | — | Fortinet Fortios | 24/6/2006 | 16/6/2026 | El módulo proxy FTP Fortinet FortiOS (FortiGate) anterior v2.80 MR12 y v3.0 MR2 permite a atacantes remotos superar el escaneo del anti-virus a través del modo Enhanced Passive (EPSV) FTP. | |
| Modificada | Media (6.4) | 1.1% | — | Greg Donald Destiney Links Script | 25/5/2006 | 16/6/2026 | SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 1.3% | — | Greg Donald Destiney Links Script | 22/5/2006 | 16/6/2026 | Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) include and (2) themes/original directories. | |
| Modificada | Media (5.8) | 1.3% | — | Greg Donald Destiney Links Script | 22/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Destiney Links Script 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) "Search" (term parameter in index.php) and (2) "Add a Site" (add.php) fields. | |
| Modificada | Media (5) | 1.8% | — | Greg Donald Destiney Links Script | 22/5/2006 | 16/6/2026 | index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the path in the resulting error message. NOTE: this issue might be resultant from a more serious issue such as directory traversal. | |
| Modificada | Media (6.4) | 1.1% | — | Greg Donald Destiney Rated Images Script | 22/5/2006 | 16/6/2026 | stats.php in Destiney Rated Images Script 0.5.0 allows remote attackers to obtain the installation path via an invalid s parameter, which displays the path in an error message. NOTE: this issue was originally claimed to be SQL injection, but CVE analysis shows that the problem is related to an invalid value that… | |
| Modificada | Media (5.8) | 1.3% | — | Greg Donald Destiney Rated Images Script | 22/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) addWeblog.php and (2) leaveComments.php in Destiney Rated Images Script 0.5.0 does not properly filter all vulnerable HTML tags, which allows remote attackers to inject arbitrary web script or HTML via Javascript in a DIV tag. | |
| Modificada | Media (5) | 1.6% | — | Fortinet28 | 21/4/2006 | 16/6/2026 | An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been disputed in followup posts that suggest that a protection feature… | |
| Modificada | Alta (10) | 2.7% | — | Fortinet FortiosFortinet Fortigate | 31/12/2005 | 16/6/2026 | The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Fortinet FortiosFortinet Fortigate | 31/12/2005 | 16/6/2026 | Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers… | |
| Modificada | Media (5) | 1.2% | — | Michael Scholz Contineo | 31/12/2005 | 16/6/2026 | Michael Scholz and Sebastian Stein Contineo 2.0, when the admin account lacks an e-mail address attribute, displays the password hash in a warning upon page reload, which might allow remote attackers to view the hash. | |
| Modificada | Alta (7.8) | 1.8% | — | Fortinet FortiosAIFortinet ForticlientAIFortinet FortimanagerAI | 29/12/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with invalid values of certain IPSec… | |
| Modificada | Media (5) | 1.4% | — | Fortinet | 1/11/2005 | 16/6/2026 | Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by… | |
| Modificada | Media (5.1) | 1.7% | — | Fortinet Antivirus | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Alta (7.5) | 1.1% | — | Fortinet Firewall | 1/6/2005 | 16/6/2026 | Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges. | |
| Modificada | Alta (7.5) | 1.3% | — | Atinegar Sigma ISP Manager | 17/5/2005 | 16/6/2026 | SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields. | |
| Modificada | Alta (10) | 71% | 💥 Exploit | Safenet Sentinel License Manager | 2/5/2005 | 16/6/2026 | Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093. | |
| Modificada | Media (4.6) | 0.39% | — | MIT KerberosMIT Kerberos 5Process Software MultinetSunos | 21/2/1996 | 16/6/2026 | Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys. |