Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.3% | — | Pmwiki | 6/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) "url links" in PmWiki 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Media (4.3) | 1.4% | — | PHP Labware Labwiki | 6/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in recentchanges.php in PHP Labware LabWiki 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the help parameter. | |
| Modificada | Media (6.8) | 1.5% | — | Wikini | 30/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WikiNi 0.4.2 and earlier allows remote attackers to inject arbitrary HTML and web script by editing a Wiki page to contain the script. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Tikiwiki Cms/groupware | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary web script or HTML via malformed nested HTML tags such as "<scr<script>ipt>" in (1) offset and (2) days parameters in (a) tiki-lastchanges.php, the (3) find and (4) offset… | |
| Modificada | Media (4.3) | 1.8% | — | Mediawiki | 26/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in the variable handler in MediaWiki 1.6.x before r14349 allows remote attackers to inject arbitrary Javascript via unspecified vectors, possibly involving the usage of the | (pipe) character. | |
| Modificada | Media (4.3) | 1.8% | — | Rwiki | 25/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Wiki content in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | Rwiki | 25/5/2006 | 16/6/2026 | The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to execute arbitrary Ruby code via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Openwiki | 19/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product. The vendor states "You cannot insert code in a wikipage or via… | |
| Modificada | Media (4.3) | 1.8% | — | Mediawiki | 30/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.5.8 and 1.4.15 allows remote attackers to inject arbitrary web script or HTML via crafted encoded links. | |
| Modificada | Alta (7.5) | 1.8% | — | Twiki | 26/3/2006 | 16/6/2026 | The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas and access restricted content in TWiki topics. | |
| Modificada | Media (4) | 1.3% | — | Twiki | 26/3/2006 | 16/6/2026 | TWiki 4.0, 4.0.1, and 20010901 through 20040904 allows remote authenticated users with edit rights to cause a denial of service (infinite recursion leading to CPU and memory consumption) via INCLUDE by URL statements that form a loop, such as a page that includes itself. | |
| Modificada | Media (4.3) | 1.2% | — | Oswiki | 23/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in OSWiki before 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the username field to (1) list.rhtml or (2) show.rhtml. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | David Barrett Qwikiwiki | 13/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to… | |
| Modificada | Media (4.3) | 1.2% | — | Andreas Gohr Dokuwiki | 12/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data." | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | David Barrett Qwikiwiki | 3/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | David Barrett Qwikiwiki | 15/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | Pmwiki | 31/1/2006 | 16/6/2026 | pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which… | |
| Modificada | Media (5) | 1.6% | — | Mediawiki | 19/1/2006 | 16/6/2026 | Unspecified vulnerability the edit comment formatting functionality in MediaWiki 1.5.x before 1.5.6 and 1.4.x before 1.4.14 allows attackers to cause a denial of service (infinite loop) via "certain malformed links." | |
| Modificada | Media (5) | 1.1% | — | Xwiki | 31/12/2005 | 16/6/2026 | The search functionality in XWiki 0.9.793 indexes cleartext user passwords, which allows remote attackers to obtain sensitive information via a search string that matches a password. | |
| Modificada | Media (4.3) | 1.4% | — | Mediawiki | 22/12/2005 | 16/6/2026 | MediaWiki before 1.5.4 uses a hard-coded "internal placeholder string", which allows remote attackers to bypass protection against cross-site scripting (XSS) attacks and execute Javascript using inline style attributes, which are processed by Internet Explorer. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Wikkawiki | 15/12/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en TextSearch en WikkaWiki 1.1.6.0 permite a atacantes remotos inyectar 'script' web o HTML de su elección mediante un parámetro de phase hex-codificado. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Cowiki | 7/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in coWiki 0.3.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter, as demonstrated using 26.html. | |
| Modificada | Alta (7.5) | 3.2% | — | Mediawiki | 6/12/2005 | 16/6/2026 | Eval injection vulnerability in MediaWiki 1.5.x before 1.5.3 allows remote attackers to execute arbitrary PHP code via the "user language option," which is used as part of a dynamic class name that is processed using the eval function. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Pmwiki | 27/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Tikiwiki Cms/groupware | 20/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter. |