Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | Tikiwiki Cms/groupware | 20/11/2005 | 16/6/2026 | tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability. | |
| Modificada | Alta (7.5) | 2.6% | — | Tikiwiki Cms/groupware | 18/11/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php. | |
| Modificada | Media (4.3) | 2.7% | — | Tikiwiki Cms/groupware | 23/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Mediawiki | 6/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet… | |
| Modificada | Media (4.3) | 1.2% | — | Mediawiki | 6/10/2005 | 16/6/2026 | Incomplete blacklist vulnerability in MediaWiki before 1.4.11 does not properly remove certain CSS inputs (HTML inline style attributes) that are processed as active content by Internet Explorer, which allows remote attackers to conduct cross-site scripting (XSS) attacks. | |
| Modificada | Media (5) | 1.9% | — | Mediawiki | 6/10/2005 | 16/6/2026 | Unspecified vulnerability in "edit submission handling" for MediaWiki 1.4.x before 1.4.10 and 1.3.x before 1.3.16 allows remote attackers to cause a denial of service (corruption of the previous submission) via a crafted URL. | |
| Modificada | Alta (7.5) | 71% | 💥 Exploit | Twiki | 16/9/2005 | 16/6/2026 | The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers. | |
| Modificada | Media (4.3) | 2.0% | — | Mediawiki | 27/7/2005 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en MediaWiki 1.4.6 y anteriores permite que atacantes remotos inyecten script web arbitrario o HTML mediante un parámetro a la plantilla de mover página. | |
| Modificada | Media (4.3) | 1.2% | — | Mediawiki | 12/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x before 1.4.6 and 1.5 before 1.5beta3 allows remote attackers to inject arbitrary web script or HTML via a parameter in the page move template, a different vulnerability than CVE-2005-1888. | |
| Modificada | Alta (7.5) | 79% | 💥 Exploit | PHP XML RPCGggeek PhpxmlrpcDrupalTikiwiki Cms/groupware+1 | 5/7/2005 | 16/6/2026 | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows… | |
| Modificada | Media (4.3) | 1.2% | — | Mediawiki | 6/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates. | |
| Modificada | Media (4.3) | 0.94% | — | Freestyle WikiFreestyle Wikilite | 31/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 2.4% | — | Tikiwiki Cms/groupware | 2/5/2005 | 16/6/2026 | TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386. | |
| Modificada | Media (5) | 1.9% | — | Mediawiki | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to delete arbitrary files or determine file existence via a parameter related to image deletion. | |
| Modificada | Media (4.3) | 1.2% | — | Mediawiki | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script. | |
| Modificada | Media (4.3) | 0.94% | — | Wackowiki | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Mediawiki | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (10) | 62% | 💥 Exploit | TwikiGentoo Linux | 1/3/2005 | 16/6/2026 | The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string. | |
| Modificada | Alta (7.5) | 2.3% | — | Twiki Imagegalleryplugin | 23/2/2005 | 16/6/2026 | The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails. | |
| Modificada | Alta (7.5) | 1.6% | — | MediawikiGentoo Linux | 22/2/2005 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users. | |
| Modificada | Media (6.8) | 4.9% | 💥 Exploit | Zwiki | 10/1/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en standard_error_message.dhtml de Zwiki posteriores a 0.10.0rc1 hasta 0.36.2 permite a atacantes remotos inyectar HTML arbitrario y script web mediante una URL malformada, que no es limpiada adecuadamente cuando se genera un mensaje de error. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | David Barrett Qwikiwiki | 4/1/2005 | 16/6/2026 | Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Tikiwiki Cms/groupware | 31/12/2004 | 16/6/2026 | TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200. | |
| Modificada | Media (4.3) | 1.2% | — | Wackowiki | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in "TextSearch" in WackoWiki 3.5 allows remote attackers to inject arbitrary web script or HTML via the "phrase" parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Jspwiki | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query parameter. |