Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1534 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 3.0% | 💥 Exploit | Phpmyteam | 10/10/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en images/smileys/smileys_packs.php en phpMyTeam 2.0, cuando register_globals está activado, permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro smileys_dir. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Qualiteam X-cart | 21/9/2006 | 16/6/2026 | Vulnerabilidad de evaluación dinámica de variable en cmpi.php en Qualiteam X-Cart 4.1.3 y anteriores permite a atacantes remotos sobreescribir variables de programa de su elección y ejecutar código PHP de su elección, como se ha demostrado en la inclusión de un fichero PHP remoto vía el parámetro xcart_dir. | |
| Modificada | Media (5.1) | 7.5% | 💥 Exploit | George Lewe Teamcal PRO | 19/9/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en includes/footer.html.inc.php en TeamCal Pro 2.8.001 y anteriores permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro tc_config[app_root]. | |
| Modificada | Media (5.1) | 13% | 💥 Exploit | Audacious Media Player Team Adplug | 13/7/2006 | 16/6/2026 | Múltiples desbordamientos de búfer basado en pila en Audacious AdPlug 2.0 y anteriores permiten a atacantes remotos con la intervención del usuario ejecutar código de su elección mediante archivos (1) DTM y (2) S3M grandes. | |
| Modificada | Media (5.1) | 5.2% | — | Audacious Media Player Team Adplug | 13/7/2006 | 16/6/2026 | Múltiples desbordamientos de búfer basados en pila en Audacious AdPlug 2.0 y anteriores permiten a atacantes remotos con la intervención de los usuarios ejecutar código de su elección a través del tamaño específico en la cabecera del paquete de los archivos (1) CFF, (2) MTK, (3) DMO, y (4) U6M. | |
| Modificada | Media (5.1) | 1.6% | — | Cmpro Team Clan Manager PRO | 9/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in cmpro_header.inc.php in Clan Manager Pro (CMPRO) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) cm_ext_server and (2) sitepath parameters. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Phplib Team Phplib | 5/6/2006 | 16/6/2026 | SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie. | |
| Modificada | Crítica (9.8) | 1.3% | — | Qualiteam X-cart | 5/6/2006 | 16/6/2026 | SQL injection vulnerability in search.php in X-Cart Gold and Pro 4.0.18, and X-Cart 4.1.0 beta 1, allows remote attackers to execute arbitrary SQL commands via the "Search for pattern" field, when the settings specify only "Search in Detailed description" and "Search also in ISBN." NOTE: the vendor disputed this issue… | |
| Modificada | Alta (7.5) | 4.8% | — | Horizontal Shooter BOROpenborSenile Team Beats OF Rage | 22/5/2006 | 16/6/2026 | Multiple format string vulnerabilities in (a) OpenBOR 2.0046 and earlier, (b) Beats of Rage (BOR) 1.0029 and earlier, and (c) Horizontal Shooter BOR (HOR) 2.0000 and earlier allow remote attackers to execute code via format string specifiers in configurations used in various mod files, as demonstrated by the (1) music… | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Skulltag Team Skulltag | 25/4/2006 | 16/6/2026 | Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string. | |
| Modificada | Media (6.8) | 25% | 💥 Exploit | Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team Services | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2)… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Phplib Team Phplib | 25/2/2006 | 16/6/2026 | Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representation of the code in a cookie. NOTE: this description was… | |
| Modificada | Alta (10) | 1.7% | — | Noofs Team Network Object Oriented File System | 18/2/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors. | |
| Modificada | Alta (10) | 1.4% | — | Open LAB Teamwork | 20/12/2005 | 16/6/2026 | Unspecified vulnerability in Teamwork 3 before alpha 1.7 has unknown impact and attack vectors, related to "a menu security bug." | |
| Modificada | Alta (7.5) | 5.1% | 💥 Exploit | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file. | |
| Modificada | Media (5) | 1.2% | — | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Gravity Board X (GBX) 1.1 allows remote attackers to obtain sensitive information via (1) a 1 in the perm parameter to deletethread.php or a direct request to (2) ban.php, (3) addnews.php, (4) banned.php, (5) boardstats.php, (6) adminform.php, (7) /forms/admininfo.php, (8) /forms/announcements.php, (9)… | |
| Modificada | Alta (7.5) | 1.6% | — | Syscp Team Syscp | 16/8/2005 | 16/6/2026 | Eval injection vulnerability in the template engine for SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via a string containing the code within "{" and "}" (curly bracket) characters, which are processed by the PHP eval function. | |
| Modificada | Media (4.3) | 1.3% | — | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X (GBX) 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the board_id parameter to deletethread.php or (2) the template. | |
| Modificada | Alta (7.5) | 1.5% | — | Syscp Team Syscp | 16/8/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in SysCP 1.2.10 and earlier allows remote attackers to execute arbitrary PHP code via the language parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Qualiteam X-cart | 1/6/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Qualiteam X-cart | 1/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode… | |
| Modificada | Media (4.6) | 2.5% | 💥 Exploit | THE PAX Team PAX Linux | 2/5/2005 | 16/6/2026 | Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass intended access restrictions and execute arbitrary code. | |
| Modificada | Media (4.3) | 20% | — | Microsoft Sharepoint Portal ServerMicrosoft Sharepoint Team Services | 2/5/2005 | 16/6/2026 | Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache. | |
| Modificada | Baja (2.1) | 0.33% | — | Fluxbox-team Fluxbot | 10/1/2005 | 16/6/2026 | FluxBox 0.9.10 and earlier versions allows local users to cause a denial of service (application crash) by calling Xman with a long -title value, possibly triggering a buffer overflow. |