Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 247 respecto a la semana anterior
Críticas / altas1338▼ 91 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1771 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 2.0% | — | Eric Integrated Development Environment | 27/9/2005 | 16/6/2026 | Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit." | |
| Modificada | Media (5) | 1.3% | — | Interchange Development Group Interchange | 27/9/2005 | 16/6/2026 | Unspecified vulnerability in Interchange 5.0.1 allows attackers 4.9.3, 5.0 before 5.0.2, and 5.2, when a catalog has been created using the (1) "mike", (2) "standard", or (3) "foundation" demo, allows attackers to inject Interchange Tag Language (ITL) elements into the forum/submit.html page. | |
| Modificada | Alta (7.5) | 1.9% | — | Interchange Development Group Interchange | 27/9/2005 | 16/6/2026 | SQL injection vulnerability in pages/forum/submit.html in Interchange 4.9.3 up to 5.2.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Azerbaijan Development Group Azdgdating | 16/9/2005 | 16/6/2026 | Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (trailing null byte) characters in the l parameter, which is used in an include_once statement. | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Whitsoft Development Slimftpd | 8/9/2005 | 16/6/2026 | SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, possibly due to a buffer overflow or off-by-one error. | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Dameware Development Mini Remote Control Server | 8/9/2005 | 16/6/2026 | Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary code via the username. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | ELM Development Group ELM | 23/8/2005 | 16/6/2026 | Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attackers to execute arbitrary code via an e-mail message with a long Expires header. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | SQL injection vulnerability in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the login field. | |
| Modificada | Media (4.3) | 1.3% | — | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X (GBX) 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the board_id parameter to deletethread.php or (2) the template. | |
| Modificada | Media (5) | 1.2% | — | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Gravity Board X (GBX) 1.1 allows remote attackers to obtain sensitive information via (1) a 1 in the perm parameter to deletethread.php or a direct request to (2) ban.php, (3) addnews.php, (4) banned.php, (5) boardstats.php, (6) adminform.php, (7) /forms/admininfo.php, (8) /forms/announcements.php, (9)… | |
| Modificada | Alta (7.5) | 5.1% | 💥 Exploit | Gravity Board X Development Team Gravity Board X | 16/8/2005 | 16/6/2026 | Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file. | |
| Modificada | Alta (9.3) | 2.7% | — | VIM Development Group VIM | 26/7/2005 | 16/6/2026 | vim 6.3 anterior a la 6.3.082, con "modelines" habilitado, permite que atacantes remotos con la implicación del usuario que ejecuten comandos arbitrarios mediante metacaracteres de shell en los comandos "glob" o "expand" de una expresión "foldexpr". | |
| Modificada | Alta (7.2) | 46% | 💥 Exploit | Whitsoft Development Slimftpd | 26/7/2005 | 16/6/2026 | Desbordamiento de búfer en SlimFTPd 3.15 y 3.16 permite que usuarios remotos autentificados ejecuten código arbitrario mediante un nombre de directorio largo en los comandos LIST, DELE o RNFR. | |
| Modificada | Media (4.6) | 0.51% | — | Oracle Jdeveloper | 18/7/2005 | 16/6/2026 | Oracle JDeveloper 9.0.4, 9.0.5, y 10.1.2 pasa el password en texto plano como parámetro cuando arranca "sqlplus", lo que permite que usuarios locales obtengan información confidencial. | |
| Modificada | Baja (2.1) | 0.87% | — | Oracle Jdeveloper | 18/7/2005 | 16/6/2026 | Oracle JDeveloper 9.0.4, 9.0.5, y 10.1.2 almacena passwords como texto plano en 1) IDEConnections.xml, (2) XSQLConfig.xml y (3) settings.xml. Esto permite que usuarios locales obtengan información confidencial. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Lighthouse Development Squirrelcart | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1) crn parameter in a show action or (2) rn parameter in a show_detail action. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Yager Development Yager Game | 2/5/2005 | 16/6/2026 | Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data than indicated by the length. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Devellion Cubecart | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Devellion Cubecart | 2/5/2005 | 16/6/2026 | CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP… | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Devellion Cubecart | 2/5/2005 | 16/6/2026 | index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message. | |
| Modificada | Baja (2.1) | 0.35% | — | Dameware Development Dameware NT UtilitiesDameware Development Miniremote Control | 2/5/2005 | 16/6/2026 | The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information. | |
| Modificada | Media (5) | 1.4% | — | Devellion Cubecart | 2/5/2005 | 16/6/2026 | CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Azerbaijan Development Group Azdgdating | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (5) | 8.3% | 💥 Exploit | Devellion Cubecart | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter. | |
| Modificada | Media (6.4) | 13% | 💥 Exploit | Yager Development Yager Game | 2/5/2005 | 16/6/2026 | Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data. |