Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.2% | — | Devellion Cubecart | 21/8/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en CubeCart 3.0.11 y anteriores permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) file, (2) x, e (3) y en (a) admin/filemanager/preview.php; y el parámetro (4) email en (b) admin/login.php. | |
| Modificada | Media (4.3) | 1.3% | — | Toenda Software Development Toendacms | 7/8/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en /toendaCMS de toendaCMS stable 1.0.3 y anteriores, y unstable 1.1 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante el parámetro s. | |
| Modificada | Media (5.8) | 1.0% | — | Simian Systems INC Siteforge Collaborative Development Platform | 12/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en index/siteforge-bugs-action/proj.siteforge de SiteForge Collaborative Development Platform 1.0.4 y anteriores permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de los parámetros (1) _status,… | |
| Modificada | Media (5.1) | 5.1% | 💥 Exploit | GeeklogToenda Software Development Toendacms | 6/7/2006 | 16/6/2026 | connectors/php/connector.php en el gestor de fichero mcpuk de FCKEditor usado en (1) Geeklog 1.4.0 a la v1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable y anteriores, y posiblemente otros productos, cuando se instala sobre Apache con mod_mime, permite a atacantes remotos subir y ejecutar código PHP de su elección a… | |
| Modificada | Media (6.8) | 1.3% | — | Toenda Software Development Toendacms | 3/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in content_footer.php in toendaCMS 0.7.0 allows remote attackers to inject arbitrary web scripts or HTML via the print_url variable. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources. | |
| Modificada | Media (6.4) | 7.5% | 💥 Exploit | Lighthouse Development Squirrelcart | 19/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter. | |
| Modificada | Media (5.1) | 3.6% | — | CAM Development CAM UnzipErik Dienske AbaktRoger Aelbrecht Tzipbuilder | 9/5/2006 | 16/6/2026 | Desbordamiento de búfer en (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 y 0.9.3-beta1, (3) CAM UnZip 4.0 y 4.3 y posiblemente en otros productos, permite a atacantes asistidos por usuario ejecutar código arbitrario a través de un archivo ZIP que contiene un archivo con un nombre de archivo largo. | |
| Modificada | Alta (10) | 4.6% | — | Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+8 | 20/4/2006 | 16/6/2026 | Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Azerbaijan Development Group Azdgvote | 13/4/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Azerbaijan Design & Development Group (AZDG) AzDGVote allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter in (1) vote.php, (2) view.php, (3) admin.php, and (4) admin/index.php. | |
| Modificada | Media (4.3) | 1.2% | — | Andries Bruinsma Flexible Development | 5/4/2006 | 16/6/2026 | Unspecified vulnerability in main.php in an unspecified "file created by Andries Bruinsma," possibly a FleXiBle Development (FXB) application, allows remote attackers to include and execute arbitrary PHP code. NOTE: this disclosure is extremely vague and has very little information about the specific vulnerability… | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Devellion Cubecart | 28/2/2006 | 16/6/2026 | CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified… | |
| Modificada | Alta (7.5) | 4.8% | — | Oracle 10G Enterprise Manager Grid ControlOracle Application ServerOracle Collaboration SuiteOracle Database Server+8 | 4/2/2006 | 16/6/2026 | Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11. | |
| Modificada | Media (4.3) | 1.4% | — | Devellion Cubecart | 18/1/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php. NOTE: the cart.php/redir and… | |
| Modificada | Alta (7.5) | 1.3% | — | Idea Development ID OY Timecan CMS | 7/1/2006 | 16/6/2026 | SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot be determined if… | |
| Modificada | Alta (7.5) | 1.3% | — | Idea Development ID OY Timecan CMS | 7/1/2006 | 16/6/2026 | SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Devellion Cubecart | 3/1/2006 | 16/6/2026 | PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter. | |
| Modificada | Media (6.5) | 2.1% | — | Toenda Software Development Toendacms | 20/12/2005 | 16/6/2026 | Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums. | |
| Modificada | Media (4.3) | 1.2% | — | Quicksquare Development Honeycomb Archive Enterprise | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Quicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise | 20/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Toenda Software Development Toendacms | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in toendaCMS 0.6.2.1, when configured to use a SQL database, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Toenda Software Development Toendacms | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in toendaCMS before 0.7 Beta allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Scriptdevelopers.net Netclassifieds | 3/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c)… | |
| Modificada | Media (5) | 1.4% | — | Toenda Software Development Toendacms | 16/11/2005 | 16/6/2026 | toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file. | |
| Modificada | Media (5) | 6.3% | 💥 Exploit | Toenda Software Development Toendacms | 16/11/2005 | 16/6/2026 | Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Devellion Cubecart | 5/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect… |