Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.8% | — | Stefan Ritt Elog WEB Logbook | 13/2/2006 | 16/6/2026 | elog before 2.5.7 r1558-4 allows remote attackers to cause a denial of service (infinite redirection) via a request with the fail parameter set to 1, which redirects to the same request. | |
| Modificada | Media (5) | 1.6% | — | Stefan Ritt Elog WEB Logbook | 13/2/2006 | 16/6/2026 | The (1) elog.c and (2) elogd.c components in elog before 2.5.7 r1558-4 generate different responses depending on whether or not a username is valid, which allows remote attackers to determine valid usernames. | |
| Modificada | Media (5) | 2.0% | — | Stefan Ritt Elog WEB Logbook | 21/1/2006 | 16/6/2026 | Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL. | |
| Modificada | Media (5) | 1.9% | — | Stefan Ritt Elog WEB Logbook | 21/1/2006 | 16/6/2026 | Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.9) | 0.31% | — | Pavel Kankovsky Echelog | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in Echelog 0.6.2 allows attackers to "exploit function stacks on some architectures," with unknown impact and attack vectors. | |
| Modificada | Media (5) | 1.1% | — | Nelogic Technologies Nephp Publisher | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in NeLogic Nephp Publisher 4.5.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) nnet_catid parameters. | |
| Modificada | Alta (7.8) | 6.1% | — | Elogd | 21/12/2005 | 16/6/2026 | Buffer overflow in ELOG elogd 2.6.0-beta4 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a URL with a long (1) cmd or (2) mode parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Nelogic Technologies Nephp Publisher Enterprise | 26/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in browse.php in Nephp Publisher Enterprise 3.04 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded keywords parameter. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Stefan Ritt Elog WEB Logbook | 2/5/2005 | 16/6/2026 | Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names. | |
| Modificada | Alta (7.5) | 1.7% | — | Stefan Ritt Elog WEB Logbook | 2/5/2005 | 16/6/2026 | ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL. | |
| Modificada | Media (6.4) | 2.1% | 💥 Exploit | Truelogik Truegalerie | 31/12/2003 | 16/6/2026 | The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1. | |
| Modificada | Alta (10) | 2.7% | — | Cafelog B2 | 22/4/2003 | 16/6/2026 | CafeLog b2 Weblog Tool 2.06pre4, with allow_fopen_url enabled, allows remote attackers to execute arbitrary PHP code via the b2inc variable. | |
| Modificada | Media (6.8) | 1.5% | — | Cafelog B2 | 22/4/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable. | |
| Modificada | Alta (7.5) | 1.4% | — | Cafelog B2 | 22/4/2003 | 16/6/2026 | SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable. | |
| Modificada | Media (6.4) | 4.3% | — | Metertek Pagelog.cgi | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter. |