Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
1582 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.8% | — | Fortinet FortiosAIFortinet ForticlientAIFortinet FortimanagerAI | 29/12/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with invalid values of certain IPSec… | |
| Modificada | Media (4.3) | 1.2% | — | Infinetsoftware Mytemplatesite | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Onlinetechtools.com Owos Lite | 27/11/2005 | 16/6/2026 | SQL injection vulnerability in search.asp in Online Work Order Suite (OWOS) Lite Edition for ASP 3.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Onlinetechtools.com Okbsys Lite | 27/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Online Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the q parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Onlinetechtools.com Oasys Lite | 27/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter. | |
| Modificada | Media (5) | 1.4% | — | Fortinet | 1/11/2005 | 16/6/2026 | Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by… | |
| Modificada | Media (5.1) | 1.7% | — | Fortinet Antivirus | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Alta (7.5) | 1.1% | — | Fortinet Firewall | 1/6/2005 | 16/6/2026 | Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges. | |
| Modificada | Alta (7.5) | 2.5% | — | GNU InetutilsAI | 31/12/2004 | 16/6/2026 | Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function. | |
| Modificada | Media (4.3) | 2.0% | — | Brad Fears Phpcodecabinet | 4/2/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Brad Fears phpCodeCabinet 0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple parameters, including (1) the sid parameter to comments.php, (2) the cid, cf, or rfd parameters to category.php, or the cid parameter to (3)… | |
| Modificada | Alta (7.5) | 2.4% | — | Rinetd | 12/5/2003 | 16/6/2026 | handleAccept en rinted anteriores a 0.62 no redimensiona adecuadamente la lista de conexiones cuando se llena y establece un array de índices incorrectamente, lo que permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante un número grande de conexiones. | |
| Modificada | Media (5) | 8.9% | 💥 Exploit | Xinetd | 5/5/2003 | 16/6/2026 | Fuga de memoria en xinetd 2.3.10 permite a atacantes remotos causar una denegación de servicio (consumición de memoria) mediante un número grande de conexiones rechazadas. | |
| Modificada | Alta (7.5) | 3.4% | — | Ka-shu Wong Gtetrinet | 31/12/2002 | 16/6/2026 | Multiple buffer overflows in (1) tetrinet_inmessage, (2) speclist_add and (3) config-getthemeinfo of GTetrinet 0.4.3 and earlier allow remote attackers to casue a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (6.8) | 1.3% | — | Onlinetools.org Phpimageview | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in phpimageview.php for PHPImageView 1.0 allows remote attackers to execute arbitrary script as other users via the pic parameter. | |
| Modificada | Media (5) | 1.4% | — | Onlinetools.org Phpimageview | 31/12/2002 | 16/6/2026 | phpimageview.php in PHPImageView 1.0 allows remote attackers to obtain sensitive information via the pw=show option, which invokes the phpinfo function. | |
| Modificada | Media (5) | 1.2% | — | Uninet Statsplus | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers. | |
| Modificada | Baja (2.1) | 0.37% | — | Xinetd | 5/9/2002 | 16/6/2026 | xinetd 2.3.4. filtra (deja ver) descriptores de ficheros para la tubería (pipe) de señales de servicios lanzados por xinetd, lo que podría permitir a esos servicios causar una denegación de servicio mediante la tubería. | |
| Modificada | Baja (2.1) | 0.34% | — | Xinet K-ashareSGI Irix | 16/5/2002 | 16/6/2026 | xkas en Xinet K-AShare 0.011.01 para IRIX permite a usuarios locales la lectura de ficheros de su elección mediante un ataque por enlace simbólico al fichero VOLICON file, que copia el fichero .HSicon en un directorio compartido. | |
| Modificada | Alta (10) | 3.6% | — | Xinetd | 6/12/2001 | 16/6/2026 | Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check. | |
| Modificada | Alta (7.5) | 3.3% | — | Xinetd | 29/8/2001 | 16/6/2026 | Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination. | |
| Modificada | Media (5) | 2.6% | — | Avtronics Inetserv | 22/8/2001 | 16/6/2026 | Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password. | |
| Modificada | Baja (3.6) | 0.36% | — | Xinetd | 10/7/2001 | 16/6/2026 | xinetd 2.1.8 and earlier runs with a default umask of 0, which could allow local users to read or modify files that are created by an application that runs under xinetd but does not set its own safe umask. | |
| Modificada | Alta (10) | 3.8% | — | Siemens Hinet LP | 19/12/2000 | 23/9/2026 | Desbordamiento de búfer en el servicio de administración web para el teléfono IP HiNet LP5100 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar comandos arbitrarios a través de una solicitud GET larga. | |
| Modificada | Alta (7.5) | 2.1% | — | Xinetd | 4/6/2000 | 16/6/2026 | xinetd 2.1.8.x does not properly restrict connections if hostnames are used for access control and the connecting host does not have a reverse DNS entry. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Avtronics Inetserv | 17/1/2000 | 16/6/2026 | Buffer overflow in InetServ 3.0 allows remote attackers to execute commands via a long GET request. |