Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1340 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)37%—Microsoft .net Framework11/7/200616/6/2026
Microsoft .NET framework 2.0 (ASP.NET) en Microsoft Windows 2000 SP4, XP SP1 y SP2, y Server 2003 hasta SP1, permite a atacantes remotos evitar las restricciones de acceso a través de "URL paths" no especificadas que pueden acceder a objetos Application Folder "explícitamente por nombre".
ModificadaMedia (5.1)16%💥 ExploitBlueshoes Framework6/6/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) APP[path][applications] parameter to (a) Bs_Faq.class.php, (2) APP[path][core] parameter to (b) fileBrowserInner.php, (c) file.php, and (d) viewer.php, and (e)…
ModificadaMedia (4)14%💥 ExploitMicrosoft .net Framework30/3/200616/6/2026
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.
ModificadaMedia (5.1)8.0%—Microsoft .net Framework30/3/200616/6/2026
Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.
ModificadaAlta (7.5)39%💥 ExploitHorde Application Framework29/3/200616/6/2026
Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.
ModificadaMedia (4.3)1.9%💥 ExploitSiteframe Beaumont19/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment).
ModificadaMedia (4.3)2.0%💥 ExploitGlen Campbell Siteframe13/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaAlta (7.5)1.2%—Glen Campbell Siteframe31/12/200516/6/2026
PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the LOCAL_PATH parameter, a different vulnerability than CVE-2005-1965.
ModificadaMedia (4.3)1.2%—Liquid Bytes Technologies Adaptive Website Framework20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in account.html in Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModificadaMedia (5)1.4%—Liquid Bytes Technologies Adaptive Website FrameworkAI20/12/200516/6/2026
Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message.
ModificadaBaja (3.5)1.6%—Horde Application Framework13/12/200516/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Horde Application Framework anteriores a 3.0.8 permiten a usuarios remotos autenticados inyectar HTML o 'script' web de su elección mediante múltiples vectores, como se ha demostrado mediante (1) el campo identidad, (2) los campos de…
ModificadaMedia (4.3)1.4%—Citrix Metaframe Secure Access ManagerCitrix Nfuse3/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.
ModificadaAlta (7.5)2.1%—Citrix Metaframe4/10/200516/6/2026
Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName).
ModificadaAlta (7.5)64%💥 ExploitATI Catalyst DriverMicrosoft .net FrameworkMicrosoft OfficeMicrosoft Project+219/8/200516/6/2026
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the…
ModificadaMedia (5)1.2%—Metasploit Framework7/8/200516/6/2026
La función StateToOptions en msfweb de Metasploit Framework 2.4 y anteriores, cuando corre con la opción -D (modo defanged, desdentado) permite a atacantes modificar variables de entorno temporales antes de que la opción de entorno "_Defanged" sea comprobada cuando se procesa la orden Exploit.
ModificadaMedia (5)1.8%—IBM Tivoli Management Framework11/7/200516/6/2026
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.
ModificadaAlta (7.5)4.0%—Glen Campbell Siteframe16/6/200516/6/2026
PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.
ModificadaMedia (4.3)1.2%—Horde Application Framework2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.
ModificadaAlta (7.5)1.3%—Citrix Metaframe Conferencing ManagerAI2/5/200516/6/2026
Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.
ModificadaBaja (2.1)0.37%—Citrix Metaframe Password Manager2/5/200516/6/2026
Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.
ModificadaMedia (4.3)16%—Microsoft .net FrameworkMono14/3/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".
ModificadaBaja (2.1)0.36%—Citrix Metaframe Password Manager31/12/200416/6/2026
The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information.
ModificadaMedia (4.3)1.3%—Horde Application Framework31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) module, (2) topic, or (3) module parameters.
ModificadaMedia (5)1.5%—Hitachi Cosminexus Portal FrameworkAI31/12/200416/6/2026
Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library.
ModificadaAlta (9.3)49%💥 ExploitMicrosoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+2028/9/200416/6/2026
Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria.