Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1781 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.3% | — | PDF Tools AG PDF Form Filling AND Flattening Tool | 24/5/2006 | 16/6/2026 | Stack-based buffer overflow in PDF Form Filling and Flattening Tool before 3.1.0.12 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via long field names. | |
| Modificada | Baja (2.1) | 0.36% | — | Iopus Secure Email Attachments | 26/4/2006 | 16/6/2026 | iOpus Secure Email Attachments (SEA), probably 1.0, does not properly handle passwords that consist of repetitions of a substring, which allows attackers to decrypt files by entering only the substring. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Matthew Dingley MD News | 13/4/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in MD News 1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Matthew Dingley MD News | 13/4/2006 | 16/6/2026 | MD News 1 allows remote attackers to bypass authentication via a direct request to a script in the Administration Area. | |
| Modificada | Media (4.3) | 1.2% | — | Matt Wright Guestbook | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information,… | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Matt Wright Guestbook | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting a message. | |
| Modificada | Media (6.5) | 1.4% | — | Greymatter | 29/3/2006 | 16/6/2026 | gm-upload.cgi in Greymatter 1.3.1 allows remote authenticated users with upload privileges to execute arbitrary programs by uploading files to locations within the web root. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Battleaxe Software Bttlxeforum | 3/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter. | |
| Modificada | Media (6.5) | 10% | — | Attachmatewrq Reflection FOR Secure IT ServerF-secure SSH Server | 15/2/2006 | 16/6/2026 | Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX… | |
| Modificada | Media (5) | 1.2% | — | Zbattle.net Zbattle Client | 1/2/2006 | 16/6/2026 | zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game. | |
| Modificada | Baja (2.1) | 0.40% | — | Richard Dawe File Extattr | 4/1/2006 | 16/6/2026 | Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors. | |
| Modificada | Alta (10) | 8.9% | — | Guiseppe Tanzilli AND Matthias Eckermann MOD Auth Pgsql | 31/12/2005 | 16/6/2026 | Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username. | |
| Modificada | Alta (7.5) | 2.2% | — | RIM Blackberry Attachment ServiceRIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Research in Motion (RIM) BlackBerry Attachment Service allows remote attackers to cause a denial of service (hang) via an e-mail attachment with a crafted TIFF file. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Afsl Games Battle Carry | 4/11/2005 | 16/6/2026 | Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server's UDP port. | |
| Modificada | Alta (7.5) | 2.0% | — | Splatt ForumAI | 23/10/2005 | 16/6/2026 | Splatt Forum 3.0 to 3.2 allows remote attackers to bypass authentication via unknown vectors. | |
| Modificada | Alta (10) | 13% | — | Symantec Antivirus Scan EngineSymantec Antivirus Scan Engine FOR Network Attached Storage | 5/10/2005 | 16/6/2026 | Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote attackers to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow. | |
| Modificada | Media (4.3) | 0.95% | — | GreymatterAI | 7/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Greymatter allows remote attackers to inject arbitrary web script or HTML via a post comment, which is recorded in a log file but not properly handled when the administrator uses "View Control Panel Log" to read the log file. | |
| Modificada | Alta (7.5) | 1.8% | — | C.j. Steele TattleAI | 8/6/2005 | 16/6/2026 | The getemails function in C.J. Steele Tattle allows remote attackers to execute arbitrary commands via shell metacharacters in certain log entries, as demonstrated using shell metacharacters in an FTP username. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Black Cactus Warrior Kings Battles | 24/5/2005 | 16/6/2026 | Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | Black Cactus Warrior KingsBlack Cactus Warrior Kings Battles | 24/5/2005 | 16/6/2026 | Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname. | |
| Modificada | Alta (7.5) | 1.1% | — | Opentools Attachment MOD | 17/5/2005 | 16/6/2026 | Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors. | |
| Modificada | Media (5) | 1.2% | — | Battleaxe Software Bttlxeforum | 14/5/2005 | 16/6/2026 | forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability. | |
| Modificada | Media (4.3) | 1.2% | — | Michael Dean Double Choco Latte | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in functions.inc.php for Double Choco Latte 0.9.4.3 allow remote attackers to inject arbitrary web script or HTML via the (1) class or (2) method name. | |
| Modificada | Media (4.3) | 1.2% | — | Matthieu Aubry Phpmyvisites | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php for phpMyVisites allow remote attackers to inject arbitrary web script or HTML via the (1) part, (2) per, or (3) site parameters. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Matthieu Aubry Phpmyvisites | 2/5/2005 | 16/6/2026 | set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter. |