Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 77% | 💥 Exploit | Tikiwiki Cms/groupware | 12/10/2007 | 16/6/2026 | tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f array parameter, which are processed by create_function. | |
| Modificada | Media (4.3) | 1.7% | — | Tikiwiki Cms/groupware | 28/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-remind_password.php in Tikiwiki (aka Tiki CMS/Groupware) 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: this issue might be related to CVE-2006-2635.7. | |
| Modificada | Media (4.3) | 1.1% | — | Mindtouch Dekiwiki | 12/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in skins/ace/popup-notopic.php in MindTouch OpenGarden DekiWiki before Gooseberry++ allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Media (4.6) | 0.30% | — | Kiwi Enterprises Kiwi Cattools | 12/2/2007 | 16/6/2026 | Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file. NOTE: this issue could be leveraged with a directory traversal vulnerability for a… | |
| Modificada | Alta (10) | 5.1% | 💥 Exploit | Kiwi Enterprises Kiwi Cattools | 12/2/2007 | 16/6/2026 | Directory traversal vulnerability in the TFTP server in Kiwi CatTools before 3.2.0 beta allows remote attackers to read arbitrary files, and upload files to arbitrary locations, via ..// (dot dot) sequences in the pathname argument to an FTP (1) GET or (2) PUT command. | |
| Modificada | Media (5) | 1.2% | — | Tikiwiki Cms/groupware | 11/12/2006 | 16/6/2026 | tiki-wiki_rss.php in Tikiwiki 1.9.5, 1.9.2, and possibly other versions allows remote attackers to obtain sensitive information (MySQL username and password) via an invalid (large or negative) ver parameter, which leaks the information in an error message. | |
| Modificada | Alta (7.5) | 2.4% | — | Tikiwiki Cms/groupware | 29/11/2006 | 16/6/2026 | tiki-register.php in TikiWiki before 1.9.7 allows remote attackers to trigger "notification-spam" via certain vectors such as a comma-separated list of addresses in the email field, related to lack of "a minimal check on email." | |
| Modificada | Media (4.3) | 1.2% | — | Tikiwiki Cms/groupware | 29/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-edit_structures.php in TikiWiki 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the pageAlias parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.97% | — | Tikiwiki Cms/groupware | 29/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-setup_base.php in TikiWiki before 1.9.7 allows remote attackers to inject arbitrary JavaScript via unspecified parameters. | |
| Modificada | Media (5) | 53% | 💥 Exploit | Tikiwiki Cms/groupware | 4/11/2006 | 16/6/2026 | Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php,… | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Tikiwiki Cms/groupware | 4/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed, nested SCRIPT elements. | |
| Modificada | Alta (7.5) | 1.4% | — | Tikiwiki Cms/groupware | 13/9/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via the (1) pid and (2) where parameters. | |
| Modificada | Alta (7.5) | 44% | 💥 Exploit | Tikiwiki Cms/groupware | 7/9/2006 | 16/6/2026 | Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory. | |
| Modificada | Media (4.3) | 1.4% | — | Tikiwiki Cms/groupware | 23/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-searchindex.php in TikiWiki 1.9.4 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.8% | — | Tikiwiki Cms/groupware | 16/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Tikiwiki Cms/groupware | 16/6/2006 | 16/6/2026 | SQL injection vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Wikiwig | 7/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WK[wkPath] parameter. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Tikiwiki Cms/groupware | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary web script or HTML via malformed nested HTML tags such as "<scr<script>ipt>" in (1) offset and (2) days parameters in (a) tiki-lastchanges.php, the (3) find and (4) offset… | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | David Barrett Qwikiwiki | 13/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | David Barrett Qwikiwiki | 3/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | David Barrett Qwikiwiki | 15/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Tikiwiki Cms/groupware | 20/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter. | |
| Modificada | Media (5) | 1.4% | — | Tikiwiki Cms/groupware | 20/11/2005 | 16/6/2026 | tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability. | |
| Modificada | Alta (7.5) | 2.6% | — | Tikiwiki Cms/groupware | 18/11/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php. | |
| Modificada | Media (4.3) | 2.7% | — | Tikiwiki Cms/groupware | 23/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. |