Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 79% | 💥 Exploit | PHP XML RPCGggeek PhpxmlrpcDrupalTikiwiki Cms/groupware+1 | 5/7/2005 | 16/6/2026 | Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows… | |
| Modificada | Alta (7.5) | 2.4% | — | Tikiwiki Cms/groupware | 2/5/2005 | 16/6/2026 | TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | David Barrett Qwikiwiki | 4/1/2005 | 16/6/2026 | Directory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00 at the end of the filename in the page parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Tikiwiki Cms/groupware | 31/12/2004 | 16/6/2026 | TikiWiki before 1.8.4.1 does not properly verify uploaded images, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2005-0200. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Tikiwiki Cms/groupware | 12/4/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sort_mode parameter in (1) tiki-usermenu.php, (2) tiki-list_file_gallery.php, (3) tiki-directory_ranking.php, (4) tiki-browse_categories.php, (5) tiki-index.php,… | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Tikiwiki Cms/groupware | 12/4/2004 | 16/6/2026 | The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL. | |
| Modificada | Alta (7.5) | 7.5% | 💥 Exploit | Tikiwiki Cms/groupware | 11/4/2004 | 16/6/2026 | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to inject arbitrary code via the (1) Theme, (2) Country, (3) Real Name, or (4) Displayed time zone fields in a User Profile, or the (5) Name, (6) Description, (7) URL, or (8) Country fields in a Directory/Add Site operation. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Tikiwiki Cms/groupware | 11/4/2004 | 16/6/2026 | Directory traversal vulnerability in the map feature (tiki-map.phtml) in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to determine the existence of arbitrary files via .. (dot dot) sequences in the mapfile parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Tikiwiki Cms/groupware | 11/4/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via via the (1) theme parameter to tiki-switch_theme.php, (2) find and priority parameters to messu-mailbox.php, (3) flag, priority, flagval, sort_mode,… | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Tikiwiki Cms/groupware | 11/4/2004 | 16/6/2026 | Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to gain sensitive information via a direct request to (1) banner_click.php, (2) categorize.php, (3) tiki-admin_include_directory.php, (4) tiki-directory_search.php, which reveal the web server path in an error message. |