Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1781 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Seattle LAB Software Slmail | 27/5/2003 | 16/6/2026 | Múltiples desbordamientos de búfer en SLMail 5.1.0.4420 permite que atacantes remotos ejecuten código arbitrario mediante (1) un argumento EHLO largo a slmail.exe, (2) un argumento XTRN largo a slmail.exe, (3) una cadena larga para POPPASSWD, o (4) un password largo para el servidor POP3. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Battleaxe Software Bttlxeforum | 12/5/2003 | 16/6/2026 | Vulnerabilidad de inyección de SQL en bttlxeForum 2.0 beta 3 y anteriores permite a atacantes remotos saltarse la autenticación mediante los campos de nombre de usuario y contraseña, y posiblemente otros campos. | |
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | John Beatty Easy PHP Photo Album | 11/5/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | |
| Modificada | Media (5) | 1.8% | — | ATT VNCTightvnc | 3/3/2003 | 16/6/2026 | The vncserver wrapper for vnc before 3.3.3r2-21 uses the rand() function instead of srand(), which causes vncserver to generate weak cookies. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Atthat.com Thatware | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in Thatware 0.3 through 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | Matt Wright Formmail | 31/12/2002 | 16/6/2026 | Matt Wright FormMail 1.9 and earlier allows remote attackers to bypass the HTTP_REFERER check and conduct unauthorized activities via (1) a blank referer, (2) a spoofed referer with a trusted domain/URL after the beginning of the referer, or (3) a spoofed referer with a trusted domain/URL in the beginning (hostname)… | |
| Modificada | Media (4.6) | 0.31% | — | Iomega Network Attached Storage | 31/12/2002 | 16/6/2026 | Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled. | |
| Modificada | Alta (7.5) | 1.1% | — | Atthat.com Thatware | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in auth.inc.php in Thatware 0.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via a base64-encoded user parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Atthat.com Thatware | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in thatfile.php in Thatware 0.3 through 0.5.2 allows remote attackers to execute arbitrary PHP code via the root_path parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Atthat.com Thatware | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in artlist.php in Thatware 0.5.2 and 0.5.3 allows remote attackers to execute arbitrary PHP code via the root_path parameter. | |
| Modificada | Media (5) | 1.4% | — | Matt Wright Formmail | 31/12/2002 | 16/6/2026 | Matt Wright FormMail 1.9 and earlier allows remote attackers to send spam or anonymous e-mail by injecting a newline character followed by CC:, BCC:, or additional TO: fields in the email and realname CGI variables. | |
| Modificada | Media (5) | 1.7% | — | Matthew Smith Micq | 23/12/2002 | 16/6/2026 | mICQ 0.4.9 and earlier allows remote attackers to cause a denial of service (crash) via malformed ICQ message types without a 0xFE separator character. | |
| Modificada | Alta (7.5) | 7.2% | 💥 Exploit | Splatt Forum | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script. | |
| Modificada | Alta (7.5) | 3.4% | — | Matthew Mondor MmftpdMatthew Mondor Mmmail | 4/10/2002 | 16/6/2026 | Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier. | |
| Modificada | Media (5) | 1.5% | — | Michael Dean Double Choco Latte | 4/10/2002 | 16/6/2026 | Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features. | |
| Modificada | Media (5) | 1.9% | — | Michael Dean Double Choco Latte | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to inject arbitrary HTML, including script, into web pages via the (1) Ticket# Find, (2) Priorities, (3) Severities, (4) Projects, (5) WO# Find, (6) Departments and (7) Users features. | |
| Modificada | Media (5) | 1.9% | — | Michael Dean Double Choco Latte | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in Double Choco Latte (DCL) before 20020706 allows remote attackers to read arbitrary files via .. (dot dot) sequences when downloading files from the Projects: Attachments feature. | |
| Modificada | Media (4.6) | 0.40% | — | ATT Winvnc ServerTightvncTridiavnc | 24/9/2002 | 16/6/2026 | Vulnerabilidad en VNC, TightVNC, y TridiaVNC permite a usuarios locales ejecutar código arbitrario como LocalSystem usando el sistema de mensajes de Win32 para evitar el GUI (Interfaz Gráfico de Úsuario) y acceder al cuadro de diálogo "Añadir nuevos clientes" | |
| Modificada | Alta (7.5) | 4.1% | — | Matt Blaze CFS | 25/6/2002 | 16/6/2026 | Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.7% | — | Noah Gray Graymatter | 25/6/2002 | 16/6/2026 | Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server… | |
| Modificada | Alta (7.5) | 1.9% | — | Matt Wright Pgpmail.pl | 30/11/2001 | 16/6/2026 | PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters. | |
| Modificada | Alta (7.5) | 1.9% | — | Guiseppe Tanzilli AND Matthias Eckermann MOD Auth Pgsql | 29/8/2001 | 16/6/2026 | The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name. | |
| Modificada | Alta (7.5) | 1.4% | — | Matt Wright Formmail | 22/8/2001 | 16/6/2026 | FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message parameters. | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Matt Tourtillott Nph-maillist | 2/7/2001 | 16/6/2026 | nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address. | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Silverplatter Webspirs | 2/6/2001 | 16/6/2026 | Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter. |