Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
149 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Fusebox | 18/5/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in fusebox5.php in Fusebox 5.5.1 allows remote attackers to execute arbitrary PHP code via a URL in the FUSEBOX_APPLICATION_PATH parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Infuseum ASP Message Board | 7/11/2007 | 16/6/2026 | SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Appfuse | 9/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in AppFuse before 2.0 Final allow remote attackers to inject arbitrary web script or HTML via unspecified input that is recorded in (1) success or (2) error messages. | |
| Modificada | Alta (7.5) | 1.1% | — | Fusetalk | 11/7/2007 | 16/6/2026 | SQL injection vulnerability in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via the FTVAR_SUBCAT (txForumID) parameter to forum/index.cfm and possibly other unspecified components, related to forum/include/error/forumerror.cfm. | |
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Fusetalk | 21/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3)… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Fusetalk | 20/6/2007 | 16/6/2026 | SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273. | |
| Modificada | Alta (7.5) | 1.1% | — | Fusetalk | 19/6/2007 | 16/6/2026 | SQL injection vulnerability in index.cfm in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.4) | 1.5% | — | PHP Fusebox | 18/1/2006 | 16/6/2026 | Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Citrix Metaframe Secure Access ManagerCitrix Nfuse | 3/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field. | |
| Modificada | Baja (2.1) | 0.36% | — | Miklos Szeredi Fuse | 23/11/2005 | 16/6/2026 | fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Macromedia Coldfusion Fusebox | 5/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm. | |
| Modificada | Media (5) | 1.2% | — | Macromedia Coldfusion Fusebox | 5/8/2005 | 16/6/2026 | ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character. | |
| Modificada | Baja (2.1) | 0.76% | 💥 Exploit | Fuse | 3/6/2005 | 16/6/2026 | FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information. | |
| Modificada | Media (6.5) | 1.8% | 💥 Exploit | Fusetalk | 31/12/2004 | 16/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm. | |
| Modificada | Media (4.3) | 1.3% | — | E-zone Media Inc. Fusetalk | 13/10/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag. | |
| Modificada | Media (5) | 1.6% | — | E-zone Media Inc. Fusetalk | 5/5/2004 | 16/6/2026 | FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm. | |
| Modificada | Media (4.3) | 0.94% | — | E-zone Media Inc. Fusetalk | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Citrix Nfuse | 12/8/2002 | 16/6/2026 | Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page. | |
| Modificada | Media (5) | 2.5% | — | Citrix Nfuse | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter. | |
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | Citrix Nfuse | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp. | |
| Modificada | Media (5) | 2.0% | — | Citrix Nfuse | 31/5/2002 | 16/6/2026 | Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters. | |
| Modificada | Media (4.6) | 0.33% | — | E-zone Media Fuse Talk | 6/12/2001 | 16/6/2026 | join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Citrix Nfuse | 18/10/2001 | 16/6/2026 | Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field. | |
| Modificada | Alta (10) | 3.1% | 💥 Exploit | Fuseware Fusemail | 13/9/1999 | 16/6/2026 | Buffer overflow in FuseMAIL POP service via long USER and PASS commands. |