Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

149 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.3%💥 ExploitFusebox18/5/200816/6/2026
PHP remote file inclusion vulnerability in fusebox5.php in Fusebox 5.5.1 allows remote attackers to execute arbitrary PHP code via a URL in the FUSEBOX_APPLICATION_PATH parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.99%💥 ExploitInfuseum ASP Message Board7/11/200716/6/2026
SQL injection vulnerability in boards/printer.asp in ASP Message Board 2.2.1c allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.1%—Appfuse9/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in messages.jsp in AppFuse before 2.0 Final allow remote attackers to inject arbitrary web script or HTML via unspecified input that is recorded in (1) success or (2) error messages.
ModificadaAlta (7.5)1.1%—Fusetalk11/7/200716/6/2026
SQL injection vulnerability in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via the FTVAR_SUBCAT (txForumID) parameter to forum/index.cfm and possibly other unspecified components, related to forum/include/error/forumerror.cfm.
ModificadaMedia (4.3)4.1%💥 ExploitFusetalk21/6/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP parameters to (a) forum/include/error/autherror.cfm, and the (3)…
ModificadaAlta (7.5)1.0%💥 ExploitFusetalk20/6/200716/6/2026
SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273.
ModificadaAlta (7.5)1.1%—Fusetalk19/6/200716/6/2026
SQL injection vulnerability in index.cfm in FuseTalk 2.0 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.4)1.5%—PHP Fusebox18/1/200616/6/2026
Cross-site scripting vulnerability in index.php in PHP Fusebox 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter.
ModificadaMedia (4.3)1.4%—Citrix Metaframe Secure Access ManagerCitrix Nfuse3/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in the login form in Citrix MetaFrame Secure Access Manager 2.0 through 2.2 and NFuse Elite 1.0 allows remote attackers to inject arbitrary web script or HTML via the username field.
ModificadaBaja (2.1)0.36%—Miklos Szeredi Fuse23/11/200516/6/2026
fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.
ModificadaMedia (4.3)3.6%💥 ExploitMacromedia Coldfusion Fusebox5/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.
ModificadaMedia (5)1.2%—Macromedia Coldfusion Fusebox5/8/200516/6/2026
ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.
ModificadaBaja (2.1)0.76%💥 ExploitFuse3/6/200516/6/2026
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.
ModificadaMedia (6.5)1.8%💥 ExploitFusetalk31/12/200416/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.
ModificadaMedia (4.3)1.3%—E-zone Media Inc. Fusetalk13/10/200416/6/2026
Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag.
ModificadaMedia (5)1.6%—E-zone Media Inc. Fusetalk5/5/200416/6/2026
FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm.
ModificadaMedia (4.3)0.94%—E-zone Media Inc. Fusetalk31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script.
ModificadaMedia (5)3.6%💥 ExploitCitrix Nfuse12/8/200216/6/2026
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.
ModificadaMedia (5)2.5%—Citrix Nfuse12/8/200216/6/2026
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.
ModificadaAlta (7.5)7.9%💥 ExploitCitrix Nfuse12/8/200216/6/2026
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.
ModificadaMedia (5)2.0%—Citrix Nfuse31/5/200216/6/2026
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.
ModificadaMedia (4.6)0.33%—E-zone Media Fuse Talk6/12/200116/6/2026
join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable.
ModificadaMedia (5)3.6%💥 ExploitCitrix Nfuse18/10/200116/6/2026
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.asp that does not provide the session field.
ModificadaAlta (10)3.1%💥 ExploitFuseware Fusemail13/9/199916/6/2026
Buffer overflow in FuseMAIL POP service via long USER and PASS commands.
Orbitaley — Vulnerabilidades