Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1534 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)3.0%💥 ExploitPhpmyteam10/10/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en images/smileys/smileys_packs.php en phpMyTeam 2.0, cuando register_globals está activado, permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro smileys_dir.
ModificadaAlta (7.5)7.0%💥 ExploitQualiteam X-cart21/9/200616/6/2026
Vulnerabilidad de evaluación dinámica de variable en cmpi.php en Qualiteam X-Cart 4.1.3 y anteriores permite a atacantes remotos sobreescribir variables de programa de su elección y ejecutar código PHP de su elección, como se ha demostrado en la inclusión de un fichero PHP remoto vía el parámetro xcart_dir.
ModificadaMedia (5.1)7.5%💥 ExploitGeorge Lewe Teamcal PRO19/9/200616/6/2026
Vulnerabilidad PHP de inclusión remota de archivo en includes/footer.html.inc.php en TeamCal Pro 2.8.001 y anteriores permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro tc_config[app_root].
ModificadaMedia (5.1)13%💥 ExploitAudacious Media Player Team Adplug13/7/200616/6/2026
Múltiples desbordamientos de búfer basado en pila en Audacious AdPlug 2.0 y anteriores permiten a atacantes remotos con la intervención del usuario ejecutar código de su elección mediante archivos (1) DTM y (2) S3M grandes.
ModificadaMedia (5.1)5.2%—Audacious Media Player Team Adplug13/7/200616/6/2026
Múltiples desbordamientos de búfer basados en pila en Audacious AdPlug 2.0 y anteriores permiten a atacantes remotos con la intervención de los usuarios ejecutar código de su elección a través del tamaño específico en la cabecera del paquete de los archivos (1) CFF, (2) MTK, (3) DMO, y (4) U6M.
ModificadaMedia (5.1)1.6%—Cmpro Team Clan Manager PRO9/6/200616/6/2026
PHP remote file inclusion vulnerability in cmpro_header.inc.php in Clan Manager Pro (CMPRO) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) cm_ext_server and (2) sitepath parameters.
ModificadaAlta (7.5)3.1%💥 ExploitPhplib Team Phplib5/6/200616/6/2026
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie.
ModificadaCrítica (9.8)1.3%—Qualiteam X-cart5/6/200616/6/2026
SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify only "Search in Detailed description" and "Search also in ISBN." NOTE: the vendor disputed this issue…
ModificadaAlta (7.5)4.8%—Horizontal Shooter BOROpenborSenile Team Beats OF Rage22/5/200616/6/2026
Multiple format string vulnerabilities in (a) OpenBOR 2.0046 and earlier, (b) Beats of Rage (BOR) 1.0029 and earlier, and (c) Horizontal Shooter BOR (HOR) 2.0000 and earlier allow remote attackers to execute code via format string specifiers in configurations used in various mod files, as demonstrated by the (1) music…
ModificadaMedia (5)3.5%💥 ExploitSkulltag Team Skulltag25/4/200616/6/2026
Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string.
ModificadaMedia (6.8)25%💥 ExploitMicrosoft Frontpage Server ExtensionsMicrosoft Sharepoint Team Services11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2)…
ModificadaAlta (7.5)3.5%💥 ExploitPhplib Team Phplib25/2/200616/6/2026
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representation of the code in a cookie. NOTE: this description was…
ModificadaAlta (10)1.7%—Noofs Team Network Object Oriented File System18/2/200616/6/2026
Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors.
ModificadaAlta (10)1.4%—Open LAB Teamwork20/12/200516/6/2026
Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug."
ModificadaAlta (7.5)5.1%💥 ExploitGravity Board X Development Team Gravity Board X16/8/200516/6/2026
Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file.
ModificadaMedia (5)1.2%—Gravity Board X Development Team Gravity Board X16/8/200516/6/2026
Gravity Board X (GBX) 1.1 allows remote attackers to obtain sensitive information via (1) a 1 in the perm parameter to deletethread.php or a direct request to (2) ban.php, (3) addnews.php, (4) banned.php, (5) boardstats.php, (6) adminform.php, (7) /forms/admininfo.php, (8) /forms/announcements.php, (9)…
ModificadaAlta (7.5)1.6%—Syscp Team Syscp16/8/200516/6/2026
Eval injection vulnerability in the template engine for SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via a string containing the code within "{" and "}" (curly bracket) characters, which are processed by the PHP eval function.
ModificadaMedia (4.3)1.3%—Gravity Board X Development Team Gravity Board X16/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X (GBX) 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the board_id parameter to deletethread.php or (2) the template.
ModificadaAlta (7.5)1.5%—Syscp Team Syscp16/8/200516/6/2026
PHP remote file inclusion vulnerability in SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via the language parameter.
ModificadaAlta (7.5)2.6%💥 ExploitGravity Board X Development Team Gravity Board X16/8/200516/6/2026
SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field.
ModificadaMedia (4.3)3.6%💥 ExploitQualiteam X-cart1/6/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to…
ModificadaAlta (7.5)2.4%💥 ExploitQualiteam X-cart1/6/200516/6/2026
Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode…
ModificadaMedia (4.6)2.5%💥 ExploitTHE PAX Team PAX Linux2/5/200516/6/2026
Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code.
ModificadaMedia (4.3)20%—Microsoft Sharepoint Portal ServerMicrosoft Sharepoint Team Services2/5/200516/6/2026
Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.
ModificadaBaja (2.1)0.33%—Fluxbox-team Fluxbot10/1/200516/6/2026
FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow.