Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.33% | — | Pcmanfm Project Pcmanfm | 15/5/2017 | 17/6/2026 | PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application unavailability). | |
| Modificada | Media (5.5) | 1.5% | — | Pacman Project Pacman | 30/1/2017 | 17/6/2026 | libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature file. | |
| Modificada | Alta (7.8) | 58% | 💥 Exploit | Pcman FTP Server | 29/9/2015 | 19/8/2026 | Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command. | |
| Modificada | Media (4.3) | 23% | — | Opendocman | 7/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Opendocman | 10/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name of an uploaded file. | |
| Modificada | Alta (10) | 66% | 💥 Exploit | Pcman FTP Server | 15/5/2014 | 19/8/2026 | Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command. | |
| Modificada | Media (6.8) | 1.2% | 💥 Exploit | Opendocman | 9/3/2014 | 17/6/2026 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Opendocman | 9/3/2014 | 17/6/2026 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter. | |
| Modificada | Media (5) | 1.4% | — | Opendocman | 24/9/2011 | 16/6/2026 | OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by User_Perms_class.php and certain other files. | |
| Modificada | Alta (7.5) | 1.0% | — | Opendocman | 27/10/2009 | 16/6/2026 | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 2.8% | 💥 Exploit | Opendocman | 26/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7)… | |
| Modificada | Alta (7.5) | 1.2% | — | Opendocman | 26/10/2009 | 16/6/2026 | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter. | |
| Modificada | Alta (7.8) | 2.3% | — | Redhat Cman | 31/3/2009 | 16/6/2026 | Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf file with many lines. NOTE: it is not clear whether this issue crosses privilege boundaries in… | |
| Modificada | Media (6.9) | 0.38% | — | Redhat Cluster ProjectRedhat CmanRedhat RgmanagerFedoraproject Fedora+1 | 30/3/2009 | 16/6/2026 | Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9. | |
| Modificada | Alta (7.2) | 0.36% | — | Gentoo CmanGentoo Fence | 15/10/2008 | 16/6/2026 | fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file. | |
| Modificada | Baja (1.9) | 0.35% | — | Gentoo CmanGentoo Fence | 15/10/2008 | 16/6/2026 | The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file. | |
| Modificada | Media (6.9) | 0.71% | 💥 Exploit | Redhat Cman | 29/9/2008 | 16/6/2026 | The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Opendocman | 20/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_message parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Opendocman | 20/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter. | |
| Modificada | Media (5) | 1.3% | — | Docman | 19/1/2007 | 16/6/2026 | DocMan 1.3 RC2 allows remote attackers to obtain sensitive information (the full path) via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.92% | — | Docman | 19/1/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in DocMan 1.3 RC2 allow attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 1.2% | — | Docman | 19/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DocMan 1.3 RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Opendocman | 3/11/2006 | 16/6/2026 | SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands via the username parameter. |