Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2837▲ 83 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1674 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Sourceshock Shockboard | 29/11/2005 | 16/6/2026 | SQL injection vulnerability in topic.php in ShockBoard 3.0 and 4.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter. | |
| Analizada | Alta (7.5) | 4.1% | 💥 Exploit | Softbizscripts Resource Repository Script | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Softbiz Resource Repository Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) sbres_id parameter in (a) details_res.php, (b) refer_friend.php, and (c) report_link.php, and (2) the sbcat_id parameter in (d) showcats.php. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Mysource | 6/11/2005 | 16/6/2026 | Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in init_mysource.php, and the PEAR_PATH parameter… | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Mysource | 6/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the bgcolor parameter in (3) insert_table.php,… | |
| Modificada | Media (4.3) | 1.9% | — | Adaptive Technology Resource Centre Atutor | 1/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the _base_href parameter in translate.php, (2) the _base_path parameter in news.inc.php, and (3) the p parameter in add_note.php. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 1/11/2005 | 16/6/2026 | Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php. | |
| Modificada | Baja (2.1) | 0.34% | — | Rogers Software Source Mgdiff Patch Viewer | 27/10/2005 | 16/6/2026 | viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Media (5.1) | 4.1% | — | Abisource Community Abiword | 23/10/2005 | 16/6/2026 | Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions… | |
| Modificada | Alta (7.5) | 84% | 💥 Exploit | Sourcefire Snort | 18/10/2005 | 16/6/2026 | Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to execute arbitrary code via a crafted UDP packet. | |
| Modificada | Alta (7.5) | 4.6% | — | Abisource Community Abiword | 28/9/2005 | 16/6/2026 | Stack-based buffer overflow in AbiWord before 2.2.10 allows attackers to execute arbitrary code via the RTF import mechanism. | |
| Modificada | Media (4.6) | 1.8% | — | Data Center Resources Avocent | 20/9/2005 | 16/6/2026 | Avocent CCM console server running firmware 2.1 CCM4850 allows remote authenticated attackers to bypass port restrictions by connecting to the server via SSH and using the connect command to access the serial port. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 16/9/2005 | 16/6/2026 | ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 16/9/2005 | 16/6/2026 | SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field. | |
| Modificada | Media (4.6) | 0.78% | — | Adaptive Technology Resource Centre Atutor | 16/9/2005 | 16/6/2026 | config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 23/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) course parameter in login.php or (2) words parameter in search.php. | |
| Modificada | Media (5) | 2.0% | — | KAF Oseo Quick AND Dirty Phpsource Printer | 6/7/2005 | 16/6/2026 | Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences. | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Adaptive Technology Resource Centre Atutor | 16/6/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5)… | |
| Modificada | Baja (2.1) | 0.36% | — | F2C Open Source Project F2C Translator | 2/5/2005 | 16/6/2026 | The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 60% | 💥 Exploit | Working Resources Inc. Badblue | 2/5/2005 | 16/6/2026 | Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter. | |
| Modificada | Media (4.6) | 0.39% | — | Debian Toolchain-sourceDebian Linux | 27/4/2005 | 16/6/2026 | Los scripts tpkg-* en el paquete toolchain-source 3.0.4 de Debian GNU/Linux 3.0 permite a usuarios locales sobreescribir ficheros arbitrarios mediante un ataque de enlaces simbólicos (symlink attack) en ficheros temporales. | |
| Modificada | Alta (7.5) | 1.6% | — | Stackworks Enterprises Information Resource Manager | 14/3/2005 | 16/6/2026 | Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers to have "potentially serious" impact, related to LDAP logins. | |
| Modificada | Baja (2.1) | 0.39% | — | Netatalk Open Source Apple File Share Protocol SuiteMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core | 9/2/2005 | 16/6/2026 | The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Alta (7.8) | 11% | 💥 Exploit | Sourcefire Snort | 31/12/2004 | 16/6/2026 | The DecodeTCPOptions function in decode.c in Snort before 2.3.0, when printing TCP/IP options using FAST output or verbose mode, allows remote attackers to cause a denial of service (crash) via packets with invalid TCP/IP options, which trigger a null dereference. | |
| Modificada | Media (4.3) | 1.4% | — | Open Source Development Network Slashcode | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) before R_2_5_0_41 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in search.pl and (2) the filter parameter in submit.pl. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Working Resources Inc. Badblue | 31/12/2004 | 16/6/2026 | BadBlue 2.4 allows remote attackers to obtain the location of the server installation path via a request for phptest.php, which includes the pathname in the source of the resulting HTML. |