Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2834▲ 81 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1674 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 10% | 💥 Exploit | ClarolineDokeos Open Source Learning AND Knowledge Management Tool | 19/9/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en inc/claro_init_local.inc.php en Claroline 1.7.7 y anteriores, como el utilizado en el Dokeos y posiblemente otros productos, permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro extAuthSource[newUser]. | |
| Modificada | Media (6.5) | 1.4% | — | Squiz Mysource Classic | 8/9/2006 | 16/6/2026 | Vulnerabilidad no especificada en MySource Classic 2.14.6, y posiblemente anteriores, permite a usuarios remotos autenticados, con privilegios de superusuario, inyectar código PHP de su elección mediante vectores no especificados relacionados con el atributo Equation en Web_Extensions - Notitia (I/II). NOTA: debido a… | |
| Modificada | Media (6.5) | 1.8% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 5/8/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en links/index.php en ATutor 1.5.3.1 y anteriores permiten a usuarios validados remotos ejecutar comandos SQL a través de los parámetros (1) desc o (2) asc . | |
| Modificada | Media (4.3) | 1.4% | — | Adaptive Technology Resource Centre Atutor | 25/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencia de comandos en sitios cruzados (XSS) en ATutor 1.5.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) lang en (1) lang parameter in (a) index_list.php y los parámetros (2) year, (3) month, y (4) day en (b) registration.php. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Imaginex-resource Imanage CMS | 24/7/2006 | 16/6/2026 | Múltiples vulnerabilidades PHP de inclusión remota de archivo en component.php en iManage CMS 4.0.12 y anteriores permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro absolute_path en (1) articles.php, (2) contact.php, (3) displaypage.php, (4) faq.php, (5) mainbody.php,… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 18/7/2006 | 16/6/2026 | ** IMPUGNADO ** Vulnerabilidad de inyección SQL en index.php en ATutor 1.5.3 permite a atacantes remotos ejecutar comandos SQL a través del parámetro fid. NOTA: este asunto ha sido impugnado por el vendedor, que indica que "la mencionada vulnerabilidad de inyección SQL no es posible". Sin embargo, el código fuente… | |
| Modificada | Baja (2.6) | 2.7% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 10/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en ATutor antes de 1.5.3 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de los parámetros (1) show_courses o (2) current_cat a (a) admin/create_course.php, show_courses a (b)… | |
| Modificada | Media (4.3) | 1.8% | — | JAM Warehouse Knowledgetree Open Source | 7/6/2006 | 16/6/2026 | view.php in KnowledgeTree Open Source 3.0.3 and earlier allows remote attackers to obtain the full installation path via a crafted fDocumentId parameter, which displays the path in the resulting error message. NOTE: this might be resultant from another vulnerability, since this vector also produces XSS. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Sourcefire Snort | 2/6/2006 | 16/6/2026 | El preprocesador HTTP Inspect (http_inspect) en Snort 2.4.0 hasta la versión 2.4.4 permite a atacantes remotos eludir reglas "uricontent" a través de un retorno de carro (\r) después de la URL y antes de la declaración HTTP. | |
| Modificada | Media (5.1) | 4.1% | 💥 Exploit | Dokeos Open Source Learning AND Knowledge Management Tool | 10/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter. | |
| Modificada | Media (5.8) | 1.2% | — | Vision Source CMS | 10/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Vision Source 0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the fields in a user's profile. | |
| Modificada | Media (4.3) | 0.41% | — | Broadcom Resource Initialization Manager | 4/5/2006 | 16/6/2026 | Unspecified vulnerability in CA Resource Initialization Manager (CAIRIM) 1.x before 20060502, as used in z/OS Common Services and the LMP component in multiple products, allows attackers to violate integrity via a certain "problem state program" that uses SVC to gain access to supervisor state, key 0. | |
| Modificada | Alta (7.5) | 1.4% | — | Sourceworkshop Newsletter | 30/3/2006 | 16/6/2026 | SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Source Workshop Vcounter | 30/3/2006 | 16/6/2026 | SQL injection vulnerability in vCounter.php in vCounter 1.0 allows remote attackers to execute arbitrary SQL commands via the URI (_SERVER[REQUEST_URI] variable). | |
| Modificada | Baja (2.6) | 0.92% | — | Ncipher Dse200 Document Sealing EngineNcipher NcoreNcipher NforceNcipher Securedb+4 | 9/3/2006 | 16/6/2026 | nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote… | |
| Modificada | Media (5) | 1.4% | — | Sourcefire Snort | 22/2/2006 | 16/6/2026 | The frag3 preprocessor in Sourcefire Snort 2.4.3 does not properly reassemble certain fragmented packets with IP options, which allows remote attackers to evade detection of certain attacks, possibly related to IP option lengths. | |
| Modificada | Alta (10) | 9.7% | — | Net-snmpSourceforge Net-snmp | 31/12/2005 | 16/6/2026 | snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a free of an incorrect variable, a different vulnerability than… | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Alta (7.5) | 1.4% | — | Digger Solutions Intranet Open SourceAI | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in projects/project-edit.asp in Digger Solutions Intranet Open Source (IOS) version 2.7.2 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. | |
| Modificada | Media (4.6) | 0.38% | — | Curtis Hawthorne Tn3270 Resource Gateway | 23/12/2005 | 16/6/2026 | Format string vulnerability in TN3270 Resource Gateway 1.1.0 allows local users to cause a denial of service and possibly execute arbitrary code via format string specifiers in syslog function calls. | |
| Modificada | Alta (7.5) | 1.5% | — | Asp-dev ASP Resources Forum | 11/12/2005 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en ASP-DEV ASP Resources Forum permiten a atacantes remotos ejecutar órdenes SQL de su elección mediante (1) el parámetro "forum_id" de forum.asp, (2) parámetros no especificados de registrer.asp, y (3) el campo "Search For" en search.asp. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 11/12/2005 | 16/6/2026 | registration.PHP en ATutor 1.4.1 p12 permite a atacantes remotos ejecutar comandos SQL de su elección mediante una dirección de correo electrónico que termina en un carácter NULL, lo que evita la comprobación mediante expresión regular de PHP. NOTA: es posible que esto sea en realidad un fallo en el código de PHP, en… | |
| Modificada | Alta (9.4) | 1.8% | — | Mambo Open Source 4.5 | 11/12/2005 | 16/6/2026 | Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character. | |
| Modificada | Alta (7.8) | 1.8% | — | Avaya Tn2602ap IP Media Resource 320 Circuit Pack | 4/12/2005 | 16/6/2026 | Memory leak in Avaya TN2602AP IP Media Resource 320 circuit pack before vintage 9 firmware allows remote attackers to cause a denial of service (memory consumption) via crafted VoIP packets. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Berlios Sourcewell | 29/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php in SourceWell 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the cnt parameter. NOTE: various reports indicate that the affected version is 1.1.3, but as of 2005-11-29, the most recent version appears to be 1.1.2. |