Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1648 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Static Store Staticstore | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in StaticStore Search Engine 1.189A and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to search.cgi, possibly the keywords parameter. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Dick Copits Pdestore | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pdestore.cgi in Dick Copits PDEstore 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the search module parameter or the (2) product and (3) cart_id parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Easybe 1-2-3 Music Store | 27/11/2005 | 16/6/2026 | SQL injection vulnerability in process.php in 1-2-3 music store allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter. | |
| Modificada | Media (4.6) | 0.38% | — | StorebackupSuse Linux | 5/10/2005 | 16/6/2026 | StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership. | |
| Modificada | Baja (2.1) | 0.36% | — | StorebackupSuse Linux | 5/10/2005 | 16/6/2026 | StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 0.36% | — | StorebackupSuse Linux | 5/10/2005 | 16/6/2026 | StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information. | |
| Modificada | Alta (7.5) | 4.6% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token. | |
| Modificada | Alta (7.5) | 4.5% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID. | |
| Modificada | Media (6.4) | 4.3% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2)… | |
| Modificada | Alta (7.5) | 2.3% | — | SUN Storedge 6130 Arrays | 16/5/2005 | 16/6/2026 | Unknown vulnerability in Sun StorEdge 6130 Arrays (SE6130) with serial numbers between 0451AWF00G and 0513AWF00J allows local users and remote attackers to delete data. | |
| Modificada | Media (6.8) | 5.7% | 💥 Exploit | Justwilliam Amazon WebstoreAI | 3/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to… | |
| Modificada | Media (5) | 1.9% | — | Oneworldstore | 2/5/2005 | 16/6/2026 | OneWorldStore allows remote attackers to cause a denial of service (application crash) via a direct request to owConnections/chksettings.asp. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Esmi Paypal Storefront | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Oneworldstore | 2/5/2005 | 16/6/2026 | owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter. | |
| Modificada | Media (5.8) | 5.6% | 💥 Exploit | Oneworldstore | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OneWorldStore allow remote attackers to inject arbitrary web script or HTML via the (1) sEmail parameter to owContactUs.asp, (2) bSub parameter to owListProduct.asp, or the (3) Name, (4) Email, or (5) Comment fields in owProductDetail.asp. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Storeportal | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Oneworldstore | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in OneWorldStore allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) owAddItem.asp or (2) owProductDetail.asp, (3) idCategory parameter to owListProduct.asp, or (4) bSpecials parameter to owListProduct.asp. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Esmi Paypal Storefront | 2/5/2005 | 16/6/2026 | Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Magicscripts E-store Kit-2 | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in catalog.php in E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary PHP code by modifying the menu and main parameters to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (4.3) | 1.0% | — | Magicscripts E-store Kit-2 | 26/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in downloadform.php in E-Store Kit-2 PayPal Edition allows remote attackers to inject arbitrary web script or HTML via the txn_id parameter. | |
| Modificada | Alta (9) | 1.7% | — | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx. | |
| Modificada | Media (4.3) | 1.4% | — | Dogpatch Software Cfwebstore | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Baja (2.1) | 0.30% | — | SUN Storedge QFSSUN Storedge Sam-qfsSUN Storeedge Performance SuiteSUN Storeedge Utilization Suite | 31/12/2004 | 16/6/2026 | Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files. | |
| Modificada | Alta (7.5) | 2.1% | — | Dogpatch Software Cfwebstore | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in index.cfm in CFWebstore 5.0 allows remote attackers to execute SQL commands via the (1) category_id, (2) product_id, or (3) feature_id parameters. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter. |