Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.9% | 💥 Exploit | Scheduling Management.com Time Tracking Software | 15/2/2006 | 16/6/2026 | edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account. | |
| Modificada | Alta (7.5) | 1.4% | — | Scheduling Management.com Time Tracking Software | 15/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in TTS Time Tracking Software 3.0 allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Redkernel Referrer Tracker | 19/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this information is unknown; portions of the details… | |
| Modificada | Media (4.3) | 1.4% | — | Widexl Download Tracker | 18/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | |
| Modificada | Media (5) | 1.4% | — | Intracom Jetspeed | 18/1/2006 | 16/6/2026 | Virata-EmWeb web server 6_1_0, as used in (1) Intracom JetSpeed 500 and 520 and (2) Allied Data Technologies CopperJet 811 RouterPlus, allows remote attackers to access privileged information, such as user lists and configuration settings, via direct HTTP requests. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Interspire Trackpoint NX | 14/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page. | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Media (4.3) | 1.5% | — | Edgewall Software Trac | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Media (4.3) | 1.4% | — | Edgewall Software Trac | 17/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Edgewall Software Trac | 7/12/2005 | 16/6/2026 | SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Edgewall Software Trac | 4/12/2005 | 16/6/2026 | SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter. | |
| Modificada | Media (6.4) | 1.4% | — | Edgewall Software Trac | 6/7/2005 | 16/6/2026 | Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts. | |
| Modificada | Media (6.4) | 1.8% | — | Edgewall Software Trac | 19/6/2005 | 16/6/2026 | Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Datatrac Activity Console | 18/5/2005 | 16/6/2026 | DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 1.1% | — | Bugtracker.netAI | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (5) | 1.5% | — | Trackercam | 30/3/2005 | 16/6/2026 | TrackerCam 5.12 y versiones anteriores, permite a atacantes remotos leer ficheros de log mediante el parámetro fn en una consulta directa al script ComGetLogFile.php3. | |
| Modificada | Media (4.3) | 1.2% | — | Trackercam | 30/3/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en TrackerCam 5.12 y versiones anteriores, permite a atacantes remotos inyectar código HTML arbitrario o script mediante una petición de conexión, la cual es almacenada en un fichero de log pero que no se maneja adecuadamente cuando el administrador visualiza… | |
| Modificada | Media (5) | 1.7% | — | Trackercam | 30/3/2005 | 16/6/2026 | TrackerCam 5.12 y versiones anteriores permiten a atacantes remotos causar la Denegación de Servicio (DoS) por caída, mediante: un gran número de conexiones con una cabecera Content-Length negativa, posiblemente provocando un error de entero sin signo, una gran cantidad de datos. | |
| Modificada | Media (5) | 66% | 💥 Exploit | Trackercam | 30/3/2005 | 16/6/2026 | Múltiples desbordamientos de búfer en TrackerCam 5.12 y versiones anteriores, permite a atacantes remotos causar la Denegación de Servicios (DoS) y posiblemente la ejecución de código arbitrario mediante: una petición HTTP con una cabecera User-Agent larga, un argumento largo a un script PHP arbitrario | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Trackercam | 30/3/2005 | 16/6/2026 | Atravesamiento de directorios en ComGetLogFile.php3 de TrackerCam 5.12 y versiones anteriores, permite a atacantes remotos la lectura de ficheros arbitrarios mediante secuencias "".."" y: ""/"" slash), """" (backslash), caracteres hexadecimales en el parámetro fn. | |
| Modificada | Media (5) | 3.6% | — | Cabextract Project Cabextract | 27/1/2005 | 16/6/2026 | Directory traversal vulnerability in cabextract before 1.1 allows remote attackers to overwrite arbitrary files via a cabinet file containing .. (dot dot) sequences in a filename. | |
| Modificada | Media (5.8) | 2.2% | 💥 Exploit | Serena Software Serena Teamtrack | 31/12/2004 | 16/6/2026 | Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and database information, and conduct cross-site scripting (XSS) attacks, via a direct request to tmtrack.dll with modified LoginPage and Template parameters. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Cvstrac | 31/12/2004 | 16/6/2026 | filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo. |