Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
1674 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 7.3% | 💥 Exploit | Working Resources Inc. Badblue | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI. | |
| Modificada | Alta (7.5) | 2.7% | — | Working Resources Inc. Badblue | 4/10/2002 | 16/6/2026 | BadBlue server stores passwords in plaintext in the ext.ini file, which could allow local and possibly remote attackers to gain privileges. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Working Resources Inc. Badblue | 4/10/2002 | 16/6/2026 | BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Working Resources Inc. Badblue | 4/10/2002 | 16/6/2026 | BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI. | |
| Modificada | Media (5) | 1.6% | — | Working Resources Inc. Badblue | 12/8/2002 | 16/6/2026 | BadBlue 1.7.0 allows remote attackers to list the contents of directories via a URL with an encoded '%' character at the end. | |
| Modificada | Media (5) | 38% | 💥 Exploit | Working Resources Inc. Badblue | 25/6/2002 | 16/6/2026 | Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL. | |
| Modificada | Alta (7.5) | 1.6% | — | Working Resources Inc. Badblue | 25/6/2002 | 16/6/2026 | Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript. | |
| Modificada | Baja (2.6) | 1.3% | — | Open Source Development Network Slashcode | 31/5/2002 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en Slash anteriores a 2.2.5, como los usados en Slashcode y otros sitios, permite a atacantes remotos robar cookies e información de autentificación de otros usuarios, mediante Javascript en una URL, probablemente en el campo formkey. | |
| Modificada | Media (4.6) | 0.35% | — | Open Source Development Network Slashcode | 31/12/2001 | 16/6/2026 | Slashcode 2.0 creates new accounts with an 8-character random password, which could allow local users to obtain session ID's from cookies and gain unauthorized access via a brute force attack. | |
| Modificada | Alta (7.2) | 0.53% | — | HP Process Resource Manager | 31/8/2001 | 16/6/2026 | Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Mimanet Source Viewer | 22/8/2001 | 16/6/2026 | Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in the 'loc' variable. | |
| Modificada | Media (5) | 2.3% | — | Working Resources Inc. Badblue | 22/8/2001 | 16/6/2026 | BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Working Resources Inc. Badblue | 3/5/2001 | 16/6/2026 | Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 1.8% | — | Sourceforge Newsdaemon | 3/5/2001 | 16/6/2026 | NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter. | |
| Modificada | Media (6.4) | 3.5% | 💥 Exploit | Working Resources Inc. Badblue | 3/5/2001 | 16/6/2026 | ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the server by directly calling ext.dll without any arguments, which produces an error message that contains the path. | |
| Modificada | Alta (10) | 4.0% | — | Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+11 | 12/3/2001 | 16/6/2026 | Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. | |
| Modificada | Alta (7.5) | 2.2% | — | Open Source Development Network Slashcode | 11/12/2000 | 16/6/2026 | The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode privileges and possibly execute arbitrary commands. | |
| Modificada | Alta (7.2) | 0.87% | 💥 Exploit | Tech-source Raptor GFX Pgx32 | 20/10/2000 | 16/6/2026 | Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options. | |
| Modificada | Alta (7.2) | 0.44% | — | Tech-source Raptor GFX Pgx32 | 20/10/2000 | 16/6/2026 | pgxconfig in the Raptor GFX configuration tool allows local users to gain privileges via a symlink attack. | |
| Modificada | Alta (7.2) | 1.0% | 💥 Exploit | Tech-source Raptor GFX Pgx32 | 20/10/2000 | 16/6/2026 | pgxconfig in the Raptor GFX configuration tool uses a relative path name for a system call to the "cp" program, which allows local users to execute arbitrary commands by modifying their path to point to an alternate "cp" program. | |
| Modificada | Baja (1.2) | 0.26% | — | Cisco Resource Manager | 31/12/1999 | 16/6/2026 | Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings. | |
| Modificada | Baja (2.1) | 0.36% | — | Cisco Resource Manager | 31/12/1999 | 16/6/2026 | Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names… | |
| Modificada | Alta (7.5) | 5.8% | — | Microsoft Backoffice Resource KIT | 22/2/1999 | 16/6/2026 | Microsoft Taskpads allows remote web sites to execute commands on the visiting user's machine via certain methods that are marked as Safe for Scripting. | |
| Modificada | Alta (10) | 5.2% | — | FMS Inc. Total VB SourcebookMicrosoft Access | 1/1/1999 | 16/6/2026 | Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data. |