Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1340 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 37% | — | Microsoft .net Framework | 11/7/2006 | 16/6/2026 | Microsoft .NET framework 2.0 (ASP.NET) en Microsoft Windows 2000 SP4, XP SP1 y SP2, y Server 2003 hasta SP1, permite a atacantes remotos evitar las restricciones de acceso a través de "URL paths" no especificadas que pueden acceder a objetos Application Folder "explícitamente por nombre". | |
| Modificada | Media (5.1) | 16% | 💥 Exploit | Blueshoes Framework | 6/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) APP[path][applications] parameter to (a) Bs_Faq.class.php, (2) APP[path][core] parameter to (b) fileBrowserInner.php, (c) file.php, and (d) viewer.php, and (e)… | |
| Modificada | Media (4) | 14% | 💥 Exploit | Microsoft .net Framework | 30/3/2006 | 16/6/2026 | Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method. | |
| Modificada | Media (5.1) | 8.0% | — | Microsoft .net Framework | 30/3/2006 | 16/6/2026 | Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name. | |
| Modificada | Alta (7.5) | 39% | 💥 Exploit | Horde Application Framework | 29/3/2006 | 16/6/2026 | Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Siteframe Beaumont | 19/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in page.php in in Siteframe Beaumont, possibly 5.0.2 or 5.0.1a, allows remote attackers to inject arbitrary web script or HTML via the comment_text parameter to the user comment page (/edit/Comment). | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Glen Campbell Siteframe | 13/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Siteframe 5.0.1 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Glen Campbell Siteframe | 31/12/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the LOCAL_PATH parameter, a different vulnerability than CVE-2005-1965. | |
| Modificada | Media (4.3) | 1.2% | — | Liquid Bytes Technologies Adaptive Website Framework | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in account.html in Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (5) | 1.4% | — | Liquid Bytes Technologies Adaptive Website FrameworkAI | 20/12/2005 | 16/6/2026 | Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message. | |
| Modificada | Baja (3.5) | 1.6% | — | Horde Application Framework | 13/12/2005 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Horde Application Framework anteriores a 3.0.8 permiten a usuarios remotos autenticados inyectar HTML o 'script' web de su elección mediante múltiples vectores, como se ha demostrado mediante (1) el campo identidad, (2) los campos de… | |
| Modificada | Media (4.3) | 1.4% | — | Citrix Metaframe Secure Access ManagerCitrix Nfuse | 3/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field. | |
| Modificada | Alta (7.5) | 2.1% | — | Citrix Metaframe | 4/10/2005 | 16/6/2026 | Citrix Metaframe Presentation Server 3.0 and 4.0 allows remote attackers to bypass policy restrictions by downloading the launch.ica file and changing the client device name (ClientName). | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | ATI Catalyst DriverMicrosoft .net FrameworkMicrosoft OfficeMicrosoft Project+2 | 19/8/2005 | 16/6/2026 | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the… | |
| Modificada | Media (5) | 1.2% | — | Metasploit Framework | 7/8/2005 | 16/6/2026 | La función StateToOptions en msfweb de Metasploit Framework 2.4 y anteriores, cuando corre con la opción -D (modo defanged, desdentado) permite a atacantes modificar variables de entorno temporales antes de que la opción de entorno "_Defanged" sea comprobada cuando se procesa la orden Exploit. | |
| Modificada | Media (5) | 1.8% | — | IBM Tivoli Management Framework | 11/7/2005 | 16/6/2026 | The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data. | |
| Modificada | Alta (7.5) | 4.0% | — | Glen Campbell Siteframe | 16/6/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Horde Application Framework | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title. | |
| Modificada | Alta (7.5) | 1.3% | — | Citrix Metaframe Conferencing ManagerAI | 2/5/2005 | 16/6/2026 | Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse. | |
| Modificada | Baja (2.1) | 0.37% | — | Citrix Metaframe Password Manager | 2/5/2005 | 16/6/2026 | Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. | |
| Modificada | Media (4.3) | 16% | — | Microsoft .net FrameworkMono | 14/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<". | |
| Modificada | Baja (2.1) | 0.36% | — | Citrix Metaframe Password Manager | 31/12/2004 | 16/6/2026 | The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. | |
| Modificada | Media (4.3) | 1.3% | — | Horde Application Framework | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the "help window" (help.php) in Horde Application Framework 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) module, (2) topic, or (3) module parameters. | |
| Modificada | Media (5) | 1.5% | — | Hitachi Cosminexus Portal FrameworkAI | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria. |