Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 53% | 💥 Exploit | Tikiwiki Cms/groupware | 4/11/2006 | 16/6/2026 | Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php,… | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Marc Logemann More.groupware | 21/9/2006 | 16/6/2026 | SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbitrary SQL commands via the new_calendarid parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Tikiwiki Cms/groupware | 13/9/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in tiki-g-admin_processes.php in Tikiwiki 1.9.4 allow remote attackers to execute arbitrary SQL commands via the (1) pid and (2) where parameters. | |
| Modificada | Alta (7.5) | 44% | 💥 Exploit | Tikiwiki Cms/groupware | 7/9/2006 | 16/6/2026 | Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory. | |
| Modificada | Media (6.4) | 3.3% | 💥 Exploit | Phpgroupware | 31/8/2006 | 16/6/2026 | Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the GLOBALS[phpgw_info][user][preferences][common][country] parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Tikiwiki Cms/groupware | 23/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-searchindex.php in TikiWiki 1.9.4 allows remote attackers to inject arbitrary web script or HTML via the highlight parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Baja (2.6) | 1.3% | — | Senokian Solutions Enterprise Groupware Systems | 27/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Enterprise Groupware System (EGS) 1.2.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Tikiwiki Cms/groupware | 16/6/2006 | 16/6/2026 | SQL injection vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |
| Modificada | Media (4.3) | 1.8% | — | Tikiwiki Cms/groupware | 16/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TikiWiki 1.9.3.2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Tikiwiki Cms/groupware | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Tikiwiki (aka Tiki CMS/Groupware) 1.9.x allow remote attackers to inject arbitrary web script or HTML via malformed nested HTML tags such as "<scr<script>ipt>" in (1) offset and (2) days parameters in (a) tiki-lastchanges.php, the (3) find and (4) offset… | |
| Modificada | Media (4.6) | 0.34% | — | Kolab Groupware Server | 14/1/2006 | 16/6/2026 | Kolab Server 2.0.1, 2.0.2 and development versions pre-2.1-20051215 and earlier, when authenticating users via secure SMTP, stores authentication credentials in plaintext in the postfix.log file, which allows local users to gain privileges. | |
| Modificada | Media (6.4) | 1.3% | — | Kolab Groupware Server | 31/12/2005 | 16/6/2026 | Kolab Server 2.0.0 and 2.0.1 does not properly handle when a large email is sent with a "." in the wrong place, which causes kolabfilter to add another ".", which might break clear-text signatures and attachments. NOTE: it is not clear whether this issue crosses privilege boundaries, so this might not be a… | |
| Modificada | Media (4.3) | 1.3% | — | Tikiwiki Cms/groupware | 20/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to inject arbitrary web script or HTML via the topics_offset parameter. | |
| Modificada | Media (5) | 1.4% | — | Tikiwiki Cms/groupware | 20/11/2005 | 16/6/2026 | tiki-view_forum_thread.php in TikiWiki 1.9.0 through 1.9.2 allows remote attackers to obtain the installation path via an invalid topics_sort_mode parameter, possibly related to an SQL injection vulnerability. | |
| Modificada | Alta (7.5) | 2.6% | — | Tikiwiki Cms/groupware | 18/11/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in Tikiwiki before 1.9.1 allow remote attackers to read arbitrary files and execute commands via (1) the suck_url parameter to tiki-editpage.php or (2) language parameter to tiki-user_preferences.php. | |
| Modificada | Media (6.8) | 3.5% | — | Phpgroupware | 18/11/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2)… | |
| Modificada | Media (4.3) | 2.7% | — | Tikiwiki Cms/groupware | 23/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in TikiWiki before 1.9.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Phpgroupware | 31/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpGroupWare 0.9.16.000 allows administrators to inject arbitrary web script or HTML by modifying the main screen message. | |
| Modificada | Alta (7.5) | 1.1% | — | Covide Groupware-crm Covide | 6/7/2005 | 16/6/2026 | SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |
| Modificada | Alta (7.5) | 79% | 💥 Exploit | PHP XML RPCGggeek PhpxmlrpcDrupalTikiwiki Cms/groupware+1 | 5/7/2005 | 16/6/2026 | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows… | |
| Modificada | Baja (2.1) | 0.37% | — | EgroupwareAI | 2/5/2005 | 16/6/2026 | eGroupWare 1.0.6 and earlier, when an e-mail is composed with an attachment but not sent, will send that attachment in the next e-mail, which may cause sensitive information to be sent to the wrong recipient. | |
| Modificada | Alta (7.5) | 2.4% | — | Tikiwiki Cms/groupware | 2/5/2005 | 16/6/2026 | TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Egroupware | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in eGroupware before 1.0.0.007 allow remote attackers to inject arbitrary web script or HTML via the (1) ab_id, (2) page, (3) type, or (4) lang parameter to index.php or (5) category_id parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Egroupware | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in eGroupware before 1.0.0.007 allow remote attackers to execute arbitrary SQL commands via the (1) filter or (2) cats_app parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Tikiwiki Cms/groupware | 31/12/2004 | 16/6/2026 | TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200. |