Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Webinsta Mailing Manager | 10/3/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Baja (2.1) | 0.69% | — | Businessobjects InfoviewBusinessobjects Webintelligence | 31/12/2004 | 16/6/2026 | Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client. | |
| Modificada | Media (4.3) | 1.2% | — | Businessobjects InfoviewBusinessobjects Webintelligence | 17/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Business Objects InfoView 5.1.4 through 5.1.8 for WebIntelligence 2.7.0 through 2.7.4 allows remote attackers to inject arbitrary web script or HTML via document names when uploading a document. | |
| Modificada | Alta (7.5) | 2.6% | — | Businessobjects Webintelligence | 31/12/2003 | 16/6/2026 | WebIntelligence 2.7.1 uses guessable user session cookies, which allows remote attackers to hijack sessions. |