Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1674 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 4.2% | 💥 Exploit | Mambo Open Source | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter. | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Netsourcecommerce Productcart | 31/12/2004 | 16/6/2026 | EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Mambo Open Source | 18/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Working Resources Inc. Badblue | 20/8/2004 | 16/6/2026 | BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address. | |
| Modificada | Baja (2.1) | 0.48% | — | HP Process Resource ManagerHP Workload Manager | 10/8/2004 | 16/6/2026 | Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files. | |
| Modificada | Alta (10) | 8.4% | — | Abisource Community AbiwordWvware | 6/8/2004 | 16/6/2026 | Desbordamiento de búfer en la función wvHandleDateTimePicture en la librería wv (wvWare) 0.7.4 a 0.7.6 y 1.0.0 permite a atacantes remotos ejecutar código de su elección mediante un documento con un campo DateTime largo. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mambo Open Source 4.5 | 16/3/2004 | 16/6/2026 | SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Mambo Open Source | 16/3/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters. | |
| Modificada | Alta (7.2) | 2.4% | 💥 Exploit | Redhat Bigmem KernelRedhat KernelRedhat Kernel DOCRedhat Kernel Source+3 | 3/3/2004 | 16/6/2026 | La función do_remap en mremap de Linux 2.2 a 2.2.25, 2.4 a 2.4.24, y 2.6 a 2.6.2 no comprueba adecuadamente el valor devuelto por la función do_munmap cuando se excede el número máximo de descriptores VMA, lo que permite a usuarios locales ganar privilegios de root, una vulnerabilidad distinta de CAN-2004-0985. | |
| Modificada | Alta (10) | 2.1% | — | Cisco Resource ManagerCisco Resource Manager EssentialsCiscoworks Common Management FoundationCiscoworks CD1 | 20/10/2003 | 16/6/2026 | CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages. | |
| Modificada | Alta (10) | 2.1% | — | Cisco Resource ManagerCisco Resource Manager EssentialsCiscoworks Common Management FoundationCiscoworks CD1 | 20/10/2003 | 16/6/2026 | CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter. | |
| Modificada | Alta (7.6) | 7.0% | 💥 Exploit | Working Resources Inc. Badblue | 9/6/2003 | 16/6/2026 | La extendisón ISAPI en BadBlue 1.7 hasta 2.2, y posiblemente versiones anteriores, modifica las dos primeras letras de la extensión de un archivo después de realizar comprobaciones de seguridad, lo que permite que atacantes remotos pasen la autentificación mediante un fichero .ats en lugar de uno .hts. | |
| Modificada | Alta (10) | 39% | 💥 Exploit | SmoothwallSourcefire Snort | 5/5/2003 | 16/6/2026 | Desbordamiento de enteros en el modulo de reensamblaje TCP (stream4) de Snort 2.0 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante números de secuencia largo en paquetes, lo que permite un desbordamiento de búfer basado en el montón. | |
| Modificada | Alta (7.5) | 1.5% | — | Working Resources Inc. Badblue | 31/3/2003 | 16/6/2026 | BadBlue 1.7 permiten a atacantes remotos eludir las protecciones de contraseñas en directorios y ficheros mediante una petición HTTP que contiene un caracter / (slash). | |
| Modificada | Media (4.3) | 0.84% | — | Sourceforge PHP Ticket | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Working Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function. | |
| Modificada | Media (6.4) | 1.2% | — | Open Source Internet Solutions | 31/12/2002 | 16/6/2026 | Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors. | |
| Modificada | Media (5) | 4.9% | — | Deerfield D2gfxWorking Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Sourceforge Mymarket | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Open Source Development Network Slashcode | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragraph <P> tag. | |
| Modificada | Alta (7.2) | 0.78% | — | Open Source Development Network Slashcode | 31/12/2002 | 16/6/2026 | Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts. | |
| Modificada | Media (5) | 1.4% | — | Working Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords. | |
| Modificada | Alta (10) | 4.1% | — | Sourcecraft Networking Utils | 31/12/2002 | 16/6/2026 | The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument. | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | Microsoft Foundation Class LibraryWorking Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and… | |
| Modificada | Alta (7.5) | 4.7% | 💥 Exploit | Working Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the… |