Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▲ 220 respecto a la semana anterior
Críticas / altas1330▼ 101 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | — | Pdfdirectory | 19/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PDFdirectory before 1.0 allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors involving (1) util.php, (2) userpref.php, (3) user.php, (4) uploadfrm.php, (5) title.php, (6) team.php, (7) stats.php, (8) page.php, (9) org.php, (10) member.php,… | |
| Modificada | Alta (7.5) | 1.1% | — | Pdfdirectory | 19/1/2006 | 16/6/2026 | PDFdirectory before 1.0 stores sensitive data in plaintext, which allows remote attackers to obtain arbitrary users' passwords by direct queries to the database, possibly via one of the SQL injection vulnerabilities. | |
| Modificada | Media (5) | 1.6% | — | IDV Directory Viewer | 5/1/2006 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en index.php en IDV Directory Viewer anteriores a 2005.1 permite a atacantes remotos ver el contenido de directorios de su elección mediante un .. (punto punto) en el parámetro "dir". | |
| Modificada | Alta (7.2) | 1.2% | — | Adobe CaptivateAdobe ContributeAdobe DirectorAdobe Dreamweaver+5 | 31/12/2005 | 16/6/2026 | Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (4.3) | 1.2% | — | Netdirect Shopengine | 28/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in NetDirect ShopEngine allows remote attackers to inject arbitrary web script or HTML via the EXPS parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Direct News | 28/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters. | |
| Modificada | Media (4.3) | 1.2% | — | MR. CGI GUY Amazon Search Directory | 6/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly the search parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 3/12/2005 | 16/6/2026 | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote… | |
| Analizada | Alta (7.5) | 4.1% | 💥 Exploit | Softbizscripts WEB Hosting Directory Script | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an… | |
| Modificada | Alta (7.8) | 9.1% | — | HP Jetdirect 635nHp-uxHP Tru64 | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP Jetdirect 635n IPv6/IPsec Print Server, and HP Tru64 UNIX 5.1B-3 and 5.1B-2/PK4, allow remote attackers to cause a denial of service via certain IKE packets, as… | |
| Modificada | Media (5.8) | 0.92% | — | IBM Tivoli Directory Server | 16/11/2005 | 16/6/2026 | slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Chipmunk Scripts Chipmunk Directory | 6/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Techno Dreams WEB Directory | 30/10/2005 | 16/6/2026 | SQL injection vulnerability in Techno Dreams Web Directory script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp. | |
| Modificada | Alta (7.5) | 3.1% | — | SUN Java System Directory Proxy ServerSUN Java System Directory ServerSUN ONE Administration ServerSUN ONE Directory Server | 20/10/2005 | 16/6/2026 | Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2… | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Novell Edirectory | 12/8/2005 | 16/6/2026 | Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors. | |
| Modificada | Baja (2.1) | 0.35% | — | Mcdata Intrepid 6064 Director SwitchMcdata Intrepid 6140 Director SwitchMcdata Sphereon 4300 Fabric SwitchMcdata Sphereon 4500 Fabric Switch | 7/8/2005 | 16/6/2026 | Vulnerabilidad desconocida en conmutadores y directores Sun McData 4300, 4500, 6064 y 6140 anteriores a E/OS 6.0.0 pueden permitir a atacantes causar una denegación de servicio (conectividad de acceso al array perdida) mediante un tormenta de multidifusión (broadcasten la red. | |
| Modificada | Media (5) | 1.6% | — | Novell Edirectory | 12/6/2005 | 16/6/2026 | Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1. | |
| Modificada | Media (4.3) | 0.97% | — | Directtopics | 14/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DirectTopics 2.1 and 2.2 allows remote attackers to inject arbitrary web script via a javascript: URL in (1) a thread or (2) an IMG tag. | |
| Modificada | Media (5) | 1.2% | — | Directtopics | 12/5/2005 | 16/6/2026 | topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to obtain sensitive information via an invalid topic parameter, which reveals the path in an error message. | |
| Modificada | Alta (7.5) | 1.2% | — | Directtopics | 12/5/2005 | 16/6/2026 | SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter. | |
| Modificada | Media (5) | 1.5% | — | Anaconda Partners Foundation Directory | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in apexec.pl for Anaconda Foundation Directory allows remote attackers to read arbitrary files via hex-encoded null characters (%00) in the middle of ".." sequences in the template parameter. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Accomplishtechnology Phpmydirectory | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary web script or HTML via the (1) subcat, (2) page, or (3) subsubcat parameter. | |
| Modificada | Media (5) | 2.5% | — | Initial Redirect Squid Proxy Plug-in | 2/5/2005 | 16/6/2026 | Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Open DC HUB Direct Connect Peer-to-peer Client | 10/1/2005 | 16/6/2026 | Buffer overflow in Open Dc Hub 0.7.14 allows remote attackers, with administrator privileges, to execute arbitrary code via a long RedirectAll command. |