Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.8% | — | Jake Olefsky Fotopholder | 21/8/2006 | 16/6/2026 | Vulnerabilidad de escalado de directorio en index.php en Fotopholder 1.8 permite a atacantes remotos leer directorios de su elección o archivos mediante un .. (punto punto) en el parámetro path. | |
| Modificada | Alta (7.5) | 67% | 💥 Exploit | EFS Software EFS FTP Server | 1/8/2006 | 16/6/2026 | Desbordamiento de búfer basado en pila en EFS Software Easy File Sharing FTP Server 2.0 permite a atacantes remotos ejecutar código de su elección a través de un argumento en el comando PASS. NOTA: la procedencia de esta información es desconocida; los detalles han sido obtenidos a partir de la información de terceros. | |
| Modificada | Alta (7.5) | 4.0% | — | Greg Roelofs Libpng | 30/6/2006 | 16/6/2026 | Desbordamiento de búfer en la función png_decompress_chunk en pngrutil.c en libpng anteriores a v1.2.12 permite a los atacantes dependientes de contexto causar una denegación de servicios y posiblemente ejecutar arbitrariamente código a través de vectores no especificado en relación a "error de procesamiento",… | |
| Modificada | Media (4.3) | 1.3% | — | EFS Software EFS WEB Server | 12/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to inject arbitrary web script or HTML via the Description field in creating a folder or uploading a file. | |
| Modificada | Alta (7.8) | 6.8% | 💥 Exploit | EFS Software EFS WEB Server | 12/3/2006 | 16/6/2026 | Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the query string argument in an HTTP GET request. | |
| Modificada | Media (6.5) | 2.8% | 💥 Exploit | EFS Software EFS WEB Server | 12/3/2006 | 16/6/2026 | Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder. | |
| Modificada | Alta (7.5) | 2.8% | — | Fscripts Fantastic News | 10/3/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable. NOTE: 2.1.4 was also reported to be vulnerable. | |
| Modificada | Media (5) | 1.3% | 💥 Exploit | Fscripts Fantastic News | 3/3/2006 | 16/6/2026 | SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846. | |
| Modificada | Alta (10) | 4.3% | — | Kyocera Fs-3830n | 19/2/2006 | 16/6/2026 | Certain unspecified Kyocera printers have a default "admin" account with a blank password, which allows remote attackers to access an administrative menu via a telnet session. | |
| Modificada | Media (5) | 1.6% | — | Kyocera Fs-3830n | 19/2/2006 | 16/6/2026 | Kyocera 3830 (aka FS-3830N) printers have a back door that allows remote attackers to read and alter configuration settings via strings that begin with "!R!SIOP0", as demonstrated using (1) a connection to to TCP port 9100 or (2) the UNIX lp command. | |
| Modificada | Alta (10) | 1.7% | — | Noofs Team Network Object Oriented File System | 18/2/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors. | |
| Modificada | Media (5) | 3.1% | — | Greg Roelofs Libpng | 31/1/2006 | 16/6/2026 | Heap-based buffer overflow in the alpha strip capability in libpng 1.2.7 allows context-dependent attackers to cause a denial of service (crash) when the png_do_strip_filler function is used to strip alpha channels out of the image. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Fscripts Fantastic News | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (4.6) | 0.60% | — | Greg Roelofs Pnmtopng | 18/11/2005 | 16/6/2026 | Off-by-one buffer overflow in pnmtopng before 2.39, when using the -alpha command line option (Alphas_Of_Color), allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNM file with exactly 256 colors. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Afsl Games Battle Carry | 4/11/2005 | 16/6/2026 | Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server's UDP port. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Fsboard | 5/7/2005 | 16/6/2026 | Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter. | |
| Modificada | Baja (2.1) | 0.38% | — | Davfs2 | 31/5/2005 | 16/6/2026 | WEB-DAV Linux File System (davfs2) 0.2.3 does not properly enforce Unix permissions, which allows local users to write arbitrary files on a davfs2 mounted filesystem. | |
| Modificada | Alta (7.5) | 2.9% | — | Ncpfs | 2/5/2005 | 16/6/2026 | Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client. | |
| Modificada | Alta (7.2) | 0.56% | — | Ncpfs | 2/5/2005 | 16/6/2026 | nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | Runtime Software Getdataback FOR Ntfs | 2/5/2005 | 16/6/2026 | GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information. | |
| Modificada | Alta (7.2) | 0.40% | — | Ncpfs | 10/1/2005 | 16/6/2026 | Desbordamiento de búfer en ncplogin y ncmap de nwclient.c de ncpfs 2.2.4, y posiblemente otras versiones, puede permitir a usuarios locales ganar privilegios mediante una opción -T larga. | |
| Modificada | Media (5) | 2.4% | — | Nfs-utilsDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+2 | 10/1/2005 | 16/6/2026 | statd en nfs-utils 1.257 y anteriores hace caso a la señal SIGPIPE, lo que permite a atacanes remotos causar una denegación de servicio (caída de proceso de servidor) mediante una conexión TCP que es terminada prematuramente. | |
| Modificada | Alta (10) | 6.0% | — | Dxfscope DXF File Format Viewer | 10/1/2005 | 16/6/2026 | Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file. | |
| Modificada | Alta (10) | 11% | — | Nfs-utilsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 10/1/2005 | 16/6/2026 | rquotad en nfs-utils (rquota_server.c) anteriores a 1.0.6-r6 en arquitecturas de 64 bits no realiza una conversión de enteros adecuadamente, lo que conduce a un desbordamiento de búfer basado en la pila y permite a atacantes remotos ejecutar código arbitrario mediante una petición NFS artesanal. | |
| Modificada | Media (5) | 1.8% | — | FsphpgalleryAI | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in index.php in FsPHPGallery before 1.2 allows remote attackers to list arbitrary directories via the dir parameter. |