Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
162 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.1% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability… | |
| Modificada | Media (5) | 1.4% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this issue was SPLIT from CVE-2014-0053 due to… | |
| Modificada | Media (5) | 2.0% | — | Gopivotal Grails-resourcesGopivotal Grails | 15/4/2014 | 17/6/2026 | The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different… | |
| Modificada | Media (4.9) | 0.95% | — | Cluster Resources Torque Resource ManagerClusterresources Torque Resource Manager | 13/1/2012 | 16/6/2026 | Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) before 2.5.9, when munge authentication is used, allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | Montala Resourcespace | 19/11/2011 | 16/6/2026 | ResourceSpace before 4.2.2833 does not properly validate access keys, which allows remote attackers to bypass intended resource restrictions via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.9% | — | Clusterresources Torque Resource Manager | 15/8/2011 | 16/6/2026 | Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authentication and submit arbitrary jobs via a modified PBS_O_HOST variable to the qsub program. | |
| Modificada | Alta (8.5) | 2.5% | — | Clusterresources Torque Resource Manager | 24/6/2011 | 16/6/2026 | Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.x before 2.4.14, 2.5.x before 2.5.6, and 3.x before 3.0.2 allow (1) remote authenticated users to gain privileges via a long Job_Name field in a qsub command to the server, and might allow (2) local users to… | |
| Modificada | Media (4.3) | 0.85% | — | Fr.simon Rundell PD Resources | 22/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | — | Fr.simon Rundell PD Resources | 22/12/2009 | 16/6/2026 | SQL injection vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | W2B Phphotresources | 16/4/2008 | 16/6/2026 | SQL injection vulnerability in cat.php in W2B phpHotResources allows remote attackers to execute arbitrary SQL commands via the kind parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Easebay Resources Login Manager | 22/1/2007 | 16/6/2026 | SQL injection vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the init_row parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Easebay Resources Login Manager | 22/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/memberlist.php in Easebay Resources Login Manager 3.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Easebay Resources Paypal Subscription Manager | 22/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/edit_member.php in Easebay Resources Paypal Subscription Manager allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Easebay Resources Paypal Subscription Manager | 22/1/2007 | 16/6/2026 | SQL injection vulnerability in admin/memberlist.php in Easebay Resources Paypal Subscription Manager allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |
| Modificada | Alta (7.2) | 0.34% | — | Cluster Resources Torque Resource Manager | 3/11/2006 | 16/6/2026 | resmom/start_exec.c in pbs_mom in TORQUE Resource Manager 2.0.0p8 and earlier allows local users to create arbitrary files via a symlink attack on (1) a job output file in /usr/spool/PBS/spool and possibly (2) a job file in /usr/spool/PBS/mom_priv/jobs. | |
| Modificada | Alta (7.5) | 1.5% | — | Asp-dev ASP Resources Forum | 11/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ASP-DEV ASP Resources Forum allow remote attackers to execute arbitrary SQL commands via the (1) forum_id parameter to forum.asp, (2) unspecified parameters to register.asp, and (3) the "Search For" field in search.asp. | |
| Modificada | Media (4.6) | 1.8% | — | Data Center Resources Avocent | 20/9/2005 | 16/6/2026 | Avocent CCM console server running firmware 2.1 CCM4850 allows remote authenticated attackers to bypass port restrictions by connecting to the server via SSH and using the connect command to access the serial port. | |
| Modificada | Alta (7.5) | 60% | 💥 Exploit | Working Resources Inc. Badblue | 2/5/2005 | 16/6/2026 | Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Working Resources Inc. Badblue | 31/12/2004 | 16/6/2026 | BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Working Resources Inc. Badblue | 20/8/2004 | 16/6/2026 | BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address. | |
| Modificada | Alta (7.6) | 7.0% | 💥 Exploit | Working Resources Inc. Badblue | 9/6/2003 | 16/6/2026 | The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension. | |
| Modificada | Alta (7.5) | 1.5% | — | Working Resources Inc. Badblue | 31/3/2003 | 16/6/2026 | BadBlue 1.7 allows remote attackers to bypass password protections for directories and files via an HTTP request containing an extra / (slash). | |
| Modificada | Media (5) | 4.9% | — | Deerfield D2gfxWorking Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents. | |
| Modificada | Media (4.3) | 7.3% | 💥 Exploit | Working Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Working Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function. |