Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.5% | — | Andy Grayndler Andys PHP Knowledgebase | 3/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (aphpkb) 0.57 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword_list parameter to (a) index.php; (2) title, (3) article, (4) author, and (5) keywords parameters to (b) submit_article.php; and (6) Question,… | |
| Modificada | Alta (7.5) | 2.0% | — | Knowledgebasepublisher | 19/3/2006 | 16/6/2026 | PHP remote file include vulnerability in PageController.php in KnowledgebasePublisher 1.2 allows remote attackers to include and execute arbitrary PHP code via a URL in the dir parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Activecampaign 1-2-allActivecampaign GeneralActivecampaign IsalientActivecampaign Knowledgebuilder+2 | 3/3/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (6.8) | 1.5% | — | Iisworks Aspknowledgebase | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ASP-Programmers.com ASPKnowledgebase allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface. | |
| Modificada | Media (4.3) | 1.8% | — | Iisworks Aspknowledgebase | 7/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in kb.asp in IISWorks ASPKnowledgeBase 2.0 allows remote attackers to inject arbitrary web script or HTML via the a parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | WSN Knowledge Base | 1/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in WSN Knowledge Base 1.2.0 and earler allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) perpage, (3) ascdesc, and (4) orderlinks in a displaycat action in (a) index.php; and the (5) id parameter in (b) comments.php and (c) memberlist.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Greywyvern Orca Knowledgebase | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Faqsystems Faqring Knowledge Base Software | 29/11/2005 | 16/6/2026 | SQL injection vulnerability in answer.php in FAQSystems FAQRing Knowledge Base Software 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Altantisfaq Altantis Knowledge Base Software | 29/11/2005 | 16/6/2026 | SQL injection vulnerability in search.php in AtlantisFAQ Knowledge Base Software 2.03 and earlier allows remote attackers to execute arbitrary SQL commands via the searchStr parameter. | |
| Modificada | Alta (7.8) | 1.8% | — | Activecampaign Knowledgebuilder | 26/11/2005 | 16/6/2026 | index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an invalid category parameter, which causes a large number of SQL queries to be processed. | |
| Modificada | Alta (7.5) | 1.2% | — | Activecampaign Knowledgebuilder | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php in ActiveCampaign KnowledgeBuilder 2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Iisworks Aspknowledgebase | 16/11/2005 | 16/6/2026 | SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in adminlogin.asp. | |
| Modificada | Alta (7.5) | 3.4% | — | Activecampaign Knowledgebuilder | 31/12/2003 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote attackers to execute arbitrary PHP code by modifying the page parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Alta (7.5) | 1.4% | — | Aladdin Knowledge Systems Esafe Gateway | 31/12/2003 | 16/6/2026 | Aladdin Knowlege Systems eSafe Gateway 3.5.126.0 does not check the entire stream of Content Vectoring Protocol (CVP) data, which allows remote attackers to bypass virus protection. | |
| Modificada | Alta (7.5) | 2.5% | — | Aladdin Knowledge Systems Esafe Gateway | 14/8/2001 | 16/6/2026 | Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags. | |
| Modificada | Alta (7.5) | 2.4% | — | Aladdin Knowledge Systems Esafe Gateway | 14/8/2001 | 16/6/2026 | Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document. | |
| Modificada | Alta (7.5) | 2.4% | — | Aladdin Knowledge Systems Esafe Gateway | 14/8/2001 | 16/6/2026 | Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined. | |
| Modificada | Media (4.6) | 0.76% | — | Aladdin Knowledge Systems Etoken | 4/5/2000 | 16/6/2026 | The Aladdin Knowledge Systems eToken device allows attackers with physical access to the device to obtain sensitive information without knowing the PIN of the owner by resetting the PIN in the EEPROM. |