Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2775▼ 14 respecto a la semana anterior
Críticas / altas1283▼ 250 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 205 respecto a la semana anterior
–

1274 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Nukescripts Nukesentinel1/10/200716/6/2026
Vulnerabilidad de inyección SQL en la función abget_admin de includes/nukesentinel.php en NukeSentinel 2.5.12 permite a atacantes remotos ejecutar comandos SQL de su elección mediante datos codificados en base64 en una cookie de administrador.
ModificadaAlta (7.5)1.1%—Nukescripts Nukesentinel1/10/200716/6/2026
Vulnerabilidad de inyección SQL en la función is_god en includes/nukesentinel.php en NukeSentinel 2.5.11 permite a atacantes remotos ejecutar comandos SQL de su eleccióna través de datos códificados-base64 en una cookie admin, un vector diferente que CVE-2007-5125.
ModificadaAlta (7.5)3.2%💥 ExploitNukescripts Nukesentinel16/3/200716/6/2026
nukesentinel.php en NukeSentinel 2.5.06 y anteriores utilizar expresiones regulares un tanto permisivas en la validación de una dirección IP, lo cual permite a atacantes remotos ejecutar comandos SQL de su elección a través del cliente-IP en la cabcera HTTO, debido a un parche incompleto de la CVE-2007-1172.
ModificadaMedia (6.8)1.0%—Nukescripts Nukesentinel16/3/200716/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en NukeSentinel versiones anteriores a 2.5.06 permite a atacantes remotos inyectar scripts web o HTML de su elección mediante vectores sin especificar relativos a "filtros para https:// y http://".
ModificadaAlta (7.5)2.1%💥 ExploitNukescripts Nukesentinel2/3/200716/6/2026
Una vulnerabilidad de inyección SQL en el archivo includes/nsbypass.php en NukeSentinel versiones 2.5.05, 2.5.11, y otras versiones anteriores a 2.5.12, permiten a los atacantes remotos ejecutar comandos SQL arbitrarios por medio de una cookie de administración.
ModificadaMedia (6.4)1.1%💥 ExploitNukescripts Nukesentinel2/3/200716/6/2026
Vulnerabilidad de inyección SQL en nukesentinel.php en NukeSentinel 2.5.05, y posiblemente anteriores, permite a atacantes remotos ejecutar comandos SQL de su elección a través de la cabecera Client-IP HTTP, también conocido como "Exploit de acceso a archivo".
ModificadaMedia (5)1.8%—Fortinet Fortios24/6/200616/6/2026
El módulo proxy FTP Fortinet FortiOS (FortiGate) anterior v2.80 MR12 y v3.0 MR2 permite a atacantes remotos superar el escaneo del anti-virus a través del modo Enhanced Passive (EPSV) FTP.
ModificadaMedia (6.4)1.1%—Greg Donald Destiney Links Script25/5/200616/6/2026
SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)1.3%—Greg Donald Destiney Links Script22/5/200616/6/2026
Destiney Links Script 2.1.2 does not protect library and other support files, which allows remote attackers to obtain the installation path via a direct URL to files in the (1) include and (2) themes/original directories.
ModificadaMedia (5.8)1.3%—Greg Donald Destiney Links Script22/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in Destiney Links Script 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) "Search" (term parameter in index.php) and (2) "Add a Site" (add.php) fields.
ModificadaMedia (5)1.8%—Greg Donald Destiney Links Script22/5/200616/6/2026
index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the path in the resulting error message. NOTE: this issue might be resultant from a more serious issue such as directory traversal.
ModificadaMedia (6.4)1.1%—Greg Donald Destiney Rated Images Script22/5/200616/6/2026
stats.php in Destiney Rated Images Script 0.5.0 allows remote attackers to obtain the installation path via an invalid s parameter, which displays the path in an error message. NOTE: this issue was originally claimed to be SQL injection, but CVE analysis shows that the problem is related to an invalid value that…
ModificadaMedia (5.8)1.3%—Greg Donald Destiney Rated Images Script22/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in (1) addWeblog.php and (2) leaveComments.php in Destiney Rated Images Script 0.5.0 does not properly filter all vulnerable HTML tags, which allows remote attackers to inject arbitrary web script or HTML via Javascript in a DIV tag.
ModificadaMedia (5)1.6%—Fortinet2821/4/200616/6/2026
An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been disputed in followup posts that suggest that a protection feature…
ModificadaAlta (10)2.7%—Fortinet FortiosFortinet Fortigate31/12/200516/6/2026
The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR command and uploading a file before the FTP server response has been sent, as demonstrated using LFTP.
ModificadaAlta (7.5)3.1%💥 ExploitFortinet FortiosFortinet Fortigate31/12/200516/6/2026
Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) HTTP request terminated with a line feed (LF) and not carriage return line feed (CRLF) or (2) HTTP request with no Host field, which is still processed by most web servers…
ModificadaMedia (5)1.2%—Michael Scholz Contineo31/12/200516/6/2026
Michael Scholz and Sebastian Stein Contineo 2.0, when the admin account lacks an e-mail address attribute, displays the password hash in a warning upon page reload, which might allow remote attackers to view the hash.
ModificadaAlta (7.8)1.8%—Fortinet FortiosAIFortinet ForticlientAIFortinet FortimanagerAI29/12/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with invalid values of certain IPSec…
ModificadaMedia (5)1.4%—Fortinet1/11/200516/6/2026
Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by…
ModificadaMedia (5.1)1.7%—Fortinet Antivirus14/10/200516/6/2026
Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are…
ModificadaAlta (7.5)1.1%—Fortinet Firewall1/6/200516/6/2026
Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.
ModificadaAlta (7.5)1.3%—Atinegar Sigma ISP Manager17/5/200516/6/2026
SQL injection vulnerability in Sigmaweb.DLL in Sigma ISP Manager 6.6 allows remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, or (3) domain fields.
ModificadaAlta (10)71%💥 ExploitSafenet Sentinel License Manager2/5/200516/6/2026
Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093.
ModificadaMedia (4.6)0.39%—MIT KerberosMIT Kerberos 5Process Software MultinetSunos21/2/199616/6/2026
Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.