Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 72% | 💥 Exploit | BMC Bladelogic Server Automation Console | 13/6/2016 | 17/6/2026 | The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure. | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | BMC Bladelogic Server Automation Console | 13/6/2016 | 17/6/2026 | The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Codelogic Freichat | 18/8/2015 | 17/6/2026 | SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php. | |
| Modificada | Media (4.3) | 1.9% | — | BarracudadriveRealtimelogic Barracudadrive | 21/5/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles.lsp, (2) name parameter to user.lsp, (3) path parameter to wizard/setuser.lsp, (4) host parameter to tunnelconstr.lsp, or (5) newpath… | |
| Modificada | Media (4.3) | 4.2% | 💥 Exploit | Themelogik Cmslogik | 13/5/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or (5) recaptcha_public parameter to admin/captcha_settings; (6)… | |
| Modificada | Media (5.8) | 1.5% | — | Mark Burdett Securelogin | 31/10/2012 | 16/6/2026 | Open redirect vulnerability in the securelogin_secure_redirect function in the Secure Login module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter. | |
| Modificada | Alta (10) | 6.8% | — | IBM Rational License KEY ServerIBM Rational License ServerIBM Telelogic License Server | 19/1/2012 | 16/6/2026 | Multiple directory traversal vulnerabilities in the vendor daemon in Rational Common Licensing in Telelogic License Server 2.0, Rational License Server 7.x, and ibmratl in IBM Rational License Key Server (RLKS) 8.0 through 8.1.2 allow remote attackers to execute arbitrary code via vectors related to save, rename, and… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Iscripts Reservelogic | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in packagedetails.php in iScripts ReserveLogic 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |
| Modificada | Media (6.8) | 0.89% | 💥 Exploit | Supercrackmunkey Simpleloginsys | 18/3/2010 | 16/6/2026 | SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Nelogic Nephp Publisher | 23/9/2009 | 16/6/2026 | SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field. | |
| Modificada | Media (4.3) | 0.88% | — | Stefan Ritt Elog WEB Logbook | 11/9/2009 | 16/6/2026 | Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS). | |
| Modificada | Alta (10) | 1.7% | — | Elog | 19/8/2009 | 16/6/2026 | Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c. | |
| Modificada | Media (4.3) | 1.3% | — | Elog | 25/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components. | |
| Modificada | Media (5) | 1.4% | — | Elog | 25/1/2008 | 16/6/2026 | The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.4% | — | Phpfreelog | 6/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in log.php in phpFreeLog alpha 0.2.0 allows remote attackers to include and execute arbitrary files via unspecified vectors. NOTE: the original disclosure is likely erroneous. | |
| Modificada | Media (6.5) | 1.5% | — | Novell Securelogin | 2/5/2007 | 16/6/2026 | Unspecified vulnerability in the ADSCHEMA utility in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to granting "users excess permissions to their own attributes." | |
| Modificada | Alta (10) | 2.3% | — | Novell Securelogin | 2/5/2007 | 16/6/2026 | Unspecified vulnerability in Novell SecureLogin (NSL) 6 SP1 before 6.0.106 has unknown impact and remote attack vectors, related to Active Directory (AD) password changes. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Cafelog B2 | 26/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in B2 Weblog and News Publishing Tool 0.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the b2inc parameter to (1) b2archives.php, (2) b2categories.php, or (3) b2mail.php. NOTE: this may overlap CVE-2002-1466. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Cafelog B2 Blog | 31/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the index parameter. | |
| Modificada | Media (5) | 3.4% | — | Stefan Ritt Elog WEB Logbook | 28/12/2006 | 16/6/2026 | The show_elog_list function in elogd.c in elog 2.6.2 and earlier allows remote authenticated users to cause a denial of service (daemon crash) by attempting to access a logbook whose name begins with "global," which results in a NULL pointer dereference. NOTE: some of these details are obtained from third party… | |
| Modificada | Baja (2.6) | 1.4% | — | Stefan Ritt Elog WEB Logbook | 7/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct function, and (2) the Type or Category values in a New entry,… | |
| Modificada | Alta (7.5) | 3.1% | — | Stefan Ritt Elog WEB Logbook | 7/11/2006 | 16/6/2026 | Multiple format string vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) an entry with an attachment whose name contains format string specifiers (el_submit function), and possibly other vectors in the (2)… | |
| Modificada | Media (5.1) | 1.4% | — | Stefan Ritt Elog WEB Logbook | 28/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Elog 2.6.1 allows remote attackers to inject arbitrary web script or HTML by editing log entries in HTML mode. | |
| Modificada | Alta (7.5) | 2.9% | — | Stefan Ritt Elog WEB Logbook | 13/2/2006 | 16/6/2026 | Buffer overflow in elogd.c in elog before 2.5.7 r1558-4 allows attackers to execute code via unspecified variables, when writing to the log file. | |
| Modificada | Alta (7.5) | 2.8% | — | Stefan Ritt Elog WEB Logbook | 13/2/2006 | 16/6/2026 | Multiple stack-based buffer overflows in elogd.c in elog before 2.5.7 r1558-4 allow attackers to cause a denial of service (application crash) and possibly execute code via long "revision attributes". |