Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2776▲ 17 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1454 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Mywebland Myevent | 11/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en viewevent.php en myWebland myEvent 1.x permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro myevent_path, un vector distinto de CVE-2006-4040. NOTA: la procedencia de esta información es desconocida; los detalles se han… | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Web-scripts Visual Events Calendar | 10/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en calendar.php de Visual Events Calendar 1.1 permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro cfg_dir. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Mywebland Myevent | 9/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en myevent.php en myWebland MyEvent 1.3 y anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro myevent_path. | |
| Modificada | Alta (7.5) | 2.1% | — | Softcomplex PHP Event Calendar | 21/7/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en calendar.php de SoftComplex PHP Event Calendar 1.4 permite a atacantes remotos ejecutar código PHP de su elección mediante un URL en el parámetro path_to_calendar, el cual sobrescribe la variable $path_to_calendar de una llamada a la función extract. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Cescripts Event Registration 2checkoutCescripts Event Registration CorporateCescripts Event Registration PaypalCescripts Event Registration Rsvp | 16/6/2006 | 16/6/2026 | Vulnerabilidad de ejecución de comandos en sitios cruzados (Cross-site scripting (XSS)) en el Registro de Eventos (Event Registration) que permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) event_id para ver-evento-details.php o (2) el parámetro select_events para… | |
| Modificada | Media (5.8) | 1.3% | — | Faktorystudios Easyevent | 9/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in easyEvent 1.2 allows remote attackers to inject arbitrary web script or HTML via the curr_year parameter. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Artmedic Webdesign Artmedic Event | 1/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Mywebland Myevent | 20/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the event_id parameter to (1) addevent.php or (2) del.php or (3) event_desc parameter to addevent.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Baja (2.6) | 1.2% | — | Mywebland Myevent | 20/4/2006 | 16/6/2026 | Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 4.4% | — | Mywebland Myevent | 20/4/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php. NOTE: vector 2 was later reported to affect 1.4 as well. | |
| Modificada | Baja (2.6) | 1.2% | — | Updi Network Enterprise AT1 Event Publisher | 17/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of Table field. | |
| Modificada | Media (4.3) | 1.2% | — | Upoint AT1 Event Publisher | 15/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_admin.htm and (b) eventpublisher_usersubmit.htm. | |
| Modificada | Media (5) | 1.4% | — | Upoint AT1 Event Publisher | 15/4/2006 | 16/6/2026 | UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt. | |
| Modificada | Alta (7.5) | 1.4% | — | Maian Events | 21/3/2006 | 16/6/2026 | SQL injection vulnerability in events.php in Maian Events 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. | |
| Modificada | Baja (3.5) | 1.1% | — | Softcomplex PHP Event Calendar | 13/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php. NOTE: while this issue was originally… | |
| Modificada | Media (5.8) | 2.9% | 💥 Exploit | Mysql Eventum | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php. | |
| Modificada | Media (6.4) | 2.0% | 💥 Exploit | Mysql Eventum | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | 88script Event Calendar | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in 88Script's Event Calendar 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter. | |
| Modificada | Alta (7.5) | 5.6% | — | Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+15 | 30/11/2005 | 16/6/2026 | Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive. | |
| Modificada | Alta (7.5) | 1.3% | — | Wwweb Concepts Events System | 5/6/2005 | 16/6/2026 | SQL injection vulnerability in login.asp for WWWeb Concepts Events System 1.0 allows remote attackers to execute arbitrary SQL commands via the password. | |
| Modificada | Media (4.6) | 0.59% | — | HP Openview Event Correlation Services | 3/5/2005 | 16/6/2026 | Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpnuke Event CalendarAI | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters. | |
| Modificada | Media (5) | 1.5% | — | ROB Sutton Php-nuke Event Calendar | 31/12/2004 | 16/6/2026 | The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message. | |
| Modificada | Media (4.3) | 1.4% | — | ROB Sutton Php-nuke Event Calendar | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments. | |
| Analizada | Media (5) | 80% | 💥 Exploit | Juniper JunosMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98se+8 | 18/8/2004 | 9/10/2026 | TCP, cuando se usa un tamaño de ventana de transmisión grande, hace más fácil a atacantes remotos adivinar números de secuencia y causar una denegación de servicio (pérdida de la conexión) en conexiones TCP persistentes inyectando repetidamente un paquete TCP RST, especialmente en protocolos que usan conexiones de… |