Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

1674 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)4.2%💥 ExploitMambo Open Source31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.
ModificadaAlta (7.5)6.8%💥 ExploitNetsourcecommerce Productcart31/12/200416/6/2026
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.
ModificadaMedia (4.3)1.8%💥 ExploitMambo Open Source18/9/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (2) mosmsg, or (3) limit parameters.
ModificadaMedia (5)3.1%💥 ExploitWorking Resources Inc. Badblue20/8/200416/6/2026
BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connections from the same IP address.
ModificadaBaja (2.1)0.48%—HP Process Resource ManagerHP Workload Manager10/8/200416/6/2026
Unknown vulnerability in HP Process Resource Manager (PRM) C.02.01[.01] and earlier, as used by HP-UX Workload Manager (WLM), allows local users to corrupt data files.
ModificadaAlta (10)8.4%—Abisource Community AbiwordWvware6/8/200416/6/2026
Desbordamiento de búfer en la función wvHandleDateTimePicture en la librería wv (wvWare) 0.7.4 a 0.7.6 y 1.0.0 permite a atacantes remotos ejecutar código de su elección mediante un documento con un campo DateTime largo.
ModificadaAlta (7.5)1.2%💥 ExploitMambo Open Source 4.516/3/200416/6/2026
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)2.0%💥 ExploitMambo Open Source16/3/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) return or (2) mos_change_template parameters.
ModificadaAlta (7.2)2.4%💥 ExploitRedhat Bigmem KernelRedhat KernelRedhat Kernel DOCRedhat Kernel Source+33/3/200416/6/2026
La función do_remap en mremap de Linux 2.2 a 2.2.25, 2.4 a 2.4.24, y 2.6 a 2.6.2 no comprueba adecuadamente el valor devuelto por la función do_munmap cuando se excede el número máximo de descriptores VMA, lo que permite a usuarios locales ganar privilegios de root, una vulnerabilidad distinta de CAN-2004-0985.
ModificadaAlta (10)2.1%—Cisco Resource ManagerCisco Resource Manager EssentialsCiscoworks Common Management FoundationCiscoworks CD120/10/200316/6/2026
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to obtain restricted information and possibly gain administrative privileges by changing the "guest" user to the Admin user on the Modify or delete users pages.
ModificadaAlta (10)2.1%—Cisco Resource ManagerCisco Resource Manager EssentialsCiscoworks Common Management FoundationCiscoworks CD120/10/200316/6/2026
CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the guest user to gain administrative privileges via a certain POST request to com.cisco.nm.cmf.servlet.CsAuthServlet, possibly involving the "cmd" parameter with a modifyUser value and a modified "priviledges" parameter.
ModificadaAlta (7.6)7.0%💥 ExploitWorking Resources Inc. Badblue9/6/200316/6/2026
La extendisón ISAPI en BadBlue 1.7 hasta 2.2, y posiblemente versiones anteriores, modifica las dos primeras letras de la extensión de un archivo después de realizar comprobaciones de seguridad, lo que permite que atacantes remotos pasen la autentificación mediante un fichero .ats en lugar de uno .hts.
ModificadaAlta (10)39%💥 ExploitSmoothwallSourcefire Snort5/5/200316/6/2026
Desbordamiento de enteros en el modulo de reensamblaje TCP (stream4) de Snort 2.0 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante números de secuencia largo en paquetes, lo que permite un desbordamiento de búfer basado en el montón.
ModificadaAlta (7.5)1.5%—Working Resources Inc. Badblue31/3/200316/6/2026
BadBlue 1.7 permiten a atacantes remotos eludir las protecciones de contraseñas en directorios y ficheros mediante una petición HTTP que contiene un caracter / (slash).
ModificadaMedia (4.3)0.84%—Sourceforge PHP Ticket31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket.
ModificadaMedia (4.3)1.7%💥 ExploitWorking Resources Inc. Badblue31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary script as other users by injecting script into the cleanSearchString() function.
ModificadaMedia (6.4)1.2%—Open Source Internet Solutions31/12/200216/6/2026
Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors.
ModificadaMedia (5)4.9%—Deerfield D2gfxWorking Resources Inc. Badblue31/12/200216/6/2026
Directory traversal vulnerability in (1) Deerfield D2Gfx 1.0.2 or (2) BadBlue Enterprise Edition 1.5.x and BadBlue Personal Edition 1.5.6 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in the script used to read Microsoft Office documents.
ModificadaMedia (4.3)1.6%💥 ExploitSourceforge Mymarket31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter.
ModificadaMedia (6.8)1.3%—Open Source Development Network Slashcode31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Slashcode CVS releases June 17 through July 1 2002 allows remote attackers to execute arbitrary script as other users by injecting script into the paragraph <P> tag.
ModificadaAlta (7.2)0.78%—Open Source Development Network Slashcode31/12/200216/6/2026
Unknown vulnerability in Slash 2.1.x and 2.2 through 2.2.2, as used in Slashcode, allows remote authenticated users to gain access to arbitrary accounts.
ModificadaMedia (5)1.4%—Working Resources Inc. Badblue31/12/200216/6/2026
soinfo.php in BadBlue 1.7.1 calls the phpinfo function, which allows remote attackers to gain sensitive information including ODBC passwords.
ModificadaAlta (10)4.1%—Sourcecraft Networking Utils31/12/200216/6/2026
The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.
ModificadaAlta (7.5)40%💥 ExploitMicrosoft Foundation Class LibraryWorking Resources Inc. Badblue31/12/200216/6/2026
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to cause a denial of service (access violation and crash) and…
ModificadaAlta (7.5)4.7%💥 ExploitWorking Resources Inc. Badblue31/12/200216/6/2026
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the…
Orbitaley — Vulnerabilidades