Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3077▲ 447 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.6% | — | SUN Java Communications Services Delegated Administrator | 7/12/2005 | 16/6/2026 | Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif. | |
| Modificada | Alta (7.5) | 5.6% | — | Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+15 | 30/11/2005 | 16/6/2026 | Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Oliver MAY Athena PHP Website Administration | 29/11/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Phpmyadmin | 24/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog. | |
| Modificada | Media (5) | 1.6% | — | Phpmyadmin | 16/11/2005 | 16/6/2026 | Vulnerabilidad de inyección de CRLF en phpMyAdmin anteriores a 2.6.4-pl4 permite a atacantes remotos conducir ataques de separación de respuesta HTTP mediante scripts no especificados. | |
| Modificada | Media (5) | 1.7% | — | Phpmyadmin | 16/11/2005 | 16/6/2026 | phpMyAdmin 2.7.0-beta1 y anteriores permiten a atacantes remotos obtener la ruta completa del servidor mediante peticiones directas a varios scripts en el directorio de bibliotecas. | |
| Modificada | Media (4.3) | 5.6% | 💥 Exploit | Phpmyadmin | 24/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Phpmyadmin | 23/10/2005 | 16/6/2026 | PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array. | |
| Modificada | Media (5) | 2.7% | — | Phpmyadmin | 23/10/2005 | 16/6/2026 | The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying… | |
| Modificada | Alta (7.5) | 3.1% | — | SUN Java System Directory Proxy ServerSUN Java System Directory ServerSUN ONE Administration ServerSUN ONE Directory Server | 20/10/2005 | 16/6/2026 | Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2… | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Phpmyadmin | 8/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Phpldapadmin Project Phpldapadmin | 2/9/2005 | 16/6/2026 | Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | Phpldapadmin Project Phpldapadmin | 2/9/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Phpldapadmin Project Phpldapadmin | 30/8/2005 | 16/6/2026 | phpldapadmin before 0.9.6c allows remote attackers to gain anonymous access to the LDAP server, even when disable_anon_bind is set, via an HTTP request to login.php with the anonymous_bind parameter set. | |
| Modificada | Alta (10) | 7.3% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets. | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5) | 3.1% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+20 | 23/8/2005 | 16/6/2026 | Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability." | |
| Modificada | Media (5) | 4.6% | 💥 Exploit | Phppgadmin | 13/7/2005 | 16/6/2026 | Vulnerabilidad de franqueo de directorioes en phpPgAdmin 3.1 hasta la 3.5.3 permite que atacantes remotos accedan a ficheros arbitrarios mediante secuencias "%2e%2e%2f" en el parámetro "formLanguage". | |
| Modificada | Baja (2.1) | 0.33% | — | Xmysqladmin | 9/6/2005 | 16/6/2026 | xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp. | |
| Modificada | Media (4.6) | 0.36% | — | Phpmyadmin | 3/5/2005 | 16/6/2026 | The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Phpmyadmin | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter. | |
| Modificada | Media (4.6) | 0.69% | — | Phpmyadmin | 2/5/2005 | 16/6/2026 | phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended. | |
| Modificada | Media (5) | 1.5% | — | Phpmyadmin | 2/5/2005 | 16/6/2026 | phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.inc.php, (7) get_foreign.lib.php, (8) display_tbl_links.lib.php,… | |
| Modificada | Alta (7.5) | 2.7% | — | Phpmyadmin | 2/5/2005 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpMyAdmin 2.6.1 allow remote attackers to execute arbitrary PHP code by modifying the (1) theme parameter to phpmyadmin.css.php or (2) cfg[Server][extension] parameter to database_interface.lib.php to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (5) | 1.4% | — | Phpmyadmin | 2/5/2005 | 16/6/2026 | phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message. |