Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.5% | — | PhpmyadminGentoo Linux | 1/3/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form, or (4) an error message generated by the internal phpMyAdmin… | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Phpmyadmin | 24/2/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter… | |
| Modificada | Media (4.3) | 1.2% | — | Alt-n Webadmin | 28/1/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Alt-n Webadmin | 28/1/2005 | 16/6/2026 | Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilitate cross-site scripting (XSS) and phishing attacks. | |
| Modificada | Baja (2.1) | 0.53% | — | Alt-n Webadmin | 28/1/2005 | 16/6/2026 | useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Phpmyadmin | 10/1/2005 | 16/6/2026 | phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to execute arbitrary commands via shell metacharacters. | |
| Modificada | Media (5) | 1.4% | — | Phpmyadmin | 10/1/2005 | 16/6/2026 | phpMyAdmin before 2.6.1, when configured with UploadDir functionality, allows remote attackers to read arbitrary files via the sql_localfile parameter. | |
| Modificada | Media (4.6) | 9.7% | 💥 Exploit | Microsoft Zero Administration KIT | 7/1/2005 | 16/6/2026 | ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe. | |
| Modificada | Media (5) | 1.2% | — | HP WEB JetadminAI | 31/12/2004 | 16/6/2026 | HP Web Jetadmin 7.5.2546 allows remote attackers to cause a denial of service (crash) via a malformed request, possibly due to a stricmp() error from an invalid use of the "$" character. | |
| Modificada | Alta (7.5) | 3.8% | — | Phpmyadmin | 31/12/2004 | 16/6/2026 | phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables. | |
| Modificada | Alta (7.5) | 9.4% | 💥 Exploit | Phpmyadmin | 31/12/2004 | 16/6/2026 | Eval injection vulnerability in left.php in phpMyAdmin 2.5.1 up to 2.5.7, when LeftFrameLight is FALSE, allows remote attackers to execute arbitrary PHP code via a crafted table name. | |
| Modificada | Alta (7.5) | 2.9% | — | Phpmyadmin | 31/12/2004 | 16/6/2026 | The MIME transformation system (transformations/text_plain__external.inc.php) in phpMyAdmin 2.5.0 up to 2.6.0-pl1 allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Leadmind Popmessenger | 24/9/2004 | 16/6/2026 | The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash. | |
| Modificada | Alta (10) | 17% | — | Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+7 | 6/8/2004 | 16/6/2026 | El demonio DHCP (DHCPD) de ISC DHCP 3.0.1rc12 y 3.0.1rc13, cuando se compila en entornos que no proveen la función vsnprintf, usa ficheros de inclusión de C que definen vsnprintf usando la función menos segura vsprintf, lo que puede ocasionar vulnerabilidades de desbordamiento de búfer que permitan una denegación de… | |
| Modificada | Alta (7.2) | 0.42% | — | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | Múltiples vulnerabilidades desconocidas en el kernel de Linux 2.4 y 2.6 permiten a usuarios locales ganar privilegios o acceder a memoria del kernel, como se ha encontrado mediante la herramienta de comprobación de código fuente "Sparse". | |
| Modificada | Baja (2.1) | 0.87% | 💥 Exploit | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | El kernel de Linux 2.4.2x y 2.6.x para x86 permite a usuarios locales causar una denegación de servicio (caída del sistema), posiblemente mediante un bucle infinito que dispara un manejador de señal con una cierta secuencia de instrucciones fsave y fstor, originalmente demostrado con el programa "crash.c". | |
| Modificada | Alta (10) | 45% | — | Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+7 | 6/8/2004 | 16/6/2026 | Desbordamiento de búfer en la capacidad de registro de sucesos (logging) del demonio DHCP (DHCPD) de ISC DHCP 3.0.1rc12 y 3.01rc13 permite a atacantes remotos causar una denegación de servión (caída del servidor) y posiblemente ejecutar código arbitrario mediante multiples opciones de nombre de máquina (hostname) en… | |
| Modificada | Baja (2.1) | 0.47% | — | Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Admin-cd FOR FirewallSuse Linux Connectivity Server+13 | 6/8/2004 | 16/6/2026 | El controlador e1000 del kernel de Linux 2.4.26 y anteriores no inicializa la memoria antes de usarla, lo que permite a usuarios locales leer porciones de la memoria del kernel. NOTA: Este problema ha sido originalmente descrito incorrectamente por otras fuentes como un "desbordamiento de búfer". | |
| Modificada | Baja (2.1) | 87% | 💥 Exploit | HP WEB Jetadmin | 24/3/2004 | 16/6/2026 | Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter. | |
| Modificada | Media (5) | 30% | 💥 Exploit | HP WEB Jetadmin | 24/3/2004 | 16/6/2026 | devices_update_printer_fw_upload.hts in HP Web JetAdmin 7.5.2546, when no password is set, allows remote attackers to upload arbitrary files to the printer directory. | |
| Modificada | Media (5) | 9.3% | 💥 Exploit | Phpmyadmin | 3/3/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en export.php en phpMyAdmin 2.5.5 y anteriores permite a atacantes remotos leer ficheros arbitrarios mediante secuencias .. (punto punto) en el parámetro what | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Gonicus System Administration | 31/12/2003 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php for GONiCUS System Administrator (GOsa) 1.0 allows remote attackers to execute arbitrary PHP code via the plugin parameter to (1) 3fax/1blocklists/index.php; (2) 6departamentadmin/index.php, (3) 5terminals/index.php, (4) 4mailinglists/index.php, (5)… | |
| Modificada | Baja (3.5) | 2.0% | 💥 Exploit | Alt-n Webadmin | 31/12/2003 | 16/6/2026 | Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with administrator privileges to (1) determine the installation path by reading the contents of the Name parameter in a link, and (2) read arbitrary files via an absolute path in the Name parameter. | |
| Modificada | Alta (7.5) | 61% | 💥 Exploit | Alt-n Webadmin | 7/8/2003 | 16/6/2026 | Desbordamiento de búfer en WebAdmin.exe de WebAdmin permite a atacantes remotos ejecutar código arbitrario mediante una petición HTTP al WebAdmin.dll con un argumento USER largo. | |
| Modificada | Media (4.6) | 0.32% | — | Platform Lsadmin | 22/5/2003 | 16/6/2026 | The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes. |