Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

165 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.8%—Stefan Ritt Elog WEB Logbook13/2/200616/6/2026
elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with the fail parameter set to 1, which redirects to the same request.
ModificadaMedia (5)1.6%—Stefan Ritt Elog WEB Logbook13/2/200616/6/2026
The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames.
ModificadaMedia (5)2.0%—Stefan Ritt Elog WEB Logbook21/1/200616/6/2026
Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.
ModificadaMedia (5)1.9%—Stefan Ritt Elog WEB Logbook21/1/200616/6/2026
Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.9)0.31%—Pavel Kankovsky Echelog31/12/200516/6/2026
Unspecified vulnerability in Echelog 0.6.2 allows attackers to "exploit function stacks on some architectures," with unknown impact and attack vectors.
ModificadaMedia (5)1.1%—Nelogic Technologies Nephp Publisher31/12/200516/6/2026
Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters.
ModificadaAlta (7.8)6.1%—Elogd21/12/200516/6/2026
Buffer overflow in ELOG elogd 2.6.0-beta4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a URL with a long (1) cmd or (2) mode parameter.
ModificadaMedia (4.3)0.94%—Nelogic Technologies Nephp Publisher Enterprise26/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in browse.php in Nephp Publisher Enterprise 3.04 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded keywords parameter.
ModificadaAlta (7.5)10%💥 ExploitStefan Ritt Elog WEB Logbook2/5/200516/6/2026
Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.
ModificadaAlta (7.5)1.7%—Stefan Ritt Elog WEB Logbook2/5/200516/6/2026
ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.
ModificadaMedia (6.4)2.1%💥 ExploitTruelogik Truegalerie31/12/200316/6/2026
The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.
ModificadaAlta (10)2.7%—Cafelog B222/4/200316/6/2026
CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable.
ModificadaMedia (6.8)1.5%—Cafelog B222/4/200316/6/2026
Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable.
ModificadaAlta (7.5)1.4%—Cafelog B222/4/200316/6/2026
SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable.
ModificadaMedia (6.4)4.3%—Metertek Pagelog.cgi19/12/200023/9/2026
Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.
Orbitaley — Vulnerabilidades