Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 79 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.6% | — | Moniwiki | 31/12/2004 | 16/6/2026 | UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attackers to upload and execute arbitrary code. | |
| Modificada | Media (5) | 0.90% | — | Mediawiki | 31/12/2004 | 16/6/2026 | Unknown vulnerability in ImagePage for MediaWiki 1.3.5, related to "filename validation," has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | Andreas Gohr Dokuwiki | 31/12/2004 | 16/6/2026 | DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks. | |
| Modificada | Media (5) | 1.4% | — | Wikindx | 31/12/2004 | 16/6/2026 | Unparsed web content delivery vulnerability in WIKINDX before 0.9.9g allows remote attackers to obtain sensitive information via a direct HTTP request to the config.inc file. | |
| Modificada | Media (4.3) | 1.3% | — | UsemodwikiAI | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in UseModWiki 1.0 allows remote attackers to inject arbitrary web script or HTML via an argument to wiki.pl. | |
| Modificada | Alta (7.5) | 1.1% | — | Mediawiki | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in MediaWiki 1.3.5 allows remote attackers to execute arbitrary SQL commands via SpecialMaintenance. | |
| Modificada | Alta (7.5) | 5.2% | 💥 Exploit | Mediawiki | 31/12/2004 | 16/6/2026 | MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.8% | — | Andreas Gohr Dokuwiki | 31/12/2004 | 16/6/2026 | DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi". | |
| Modificada | Media (4.3) | 1.2% | — | Mediawiki | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (6.8) | 2.0% | — | Mediawiki | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.5 allow remote attackers to execute arbitrary scripts and/or SQL queries via (1) the UnicodeConverter extension, (2) raw page views, (3) SpecialIpblocklist, (4) SpecialEmailuser, (5) SpecialMaintenance, and (6) ImagePage. | |
| Modificada | Media (4.3) | 1.3% | — | Moniwiki | 25/10/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Tikiwiki Cms/groupware | 12/4/2004 | 16/6/2026 | The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Tikiwiki Cms/groupware | 12/4/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php,… | |
| Modificada | Alta (7.5) | 7.5% | 💥 Exploit | Tikiwiki Cms/groupware | 11/4/2004 | 16/6/2026 | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Tikiwiki Cms/groupware | 11/4/2004 | 16/6/2026 | Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Tikiwiki Cms/groupware | 11/4/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php, (3) flag, priority, flagval, sort_mode,… | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Tikiwiki Cms/groupware | 11/4/2004 | 16/6/2026 | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Php-wiki | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter. |