Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 247 respecto a la semana anterior
Críticas / altas1338▼ 91 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 1.3% | — | R2xdesign Qlitenews | 1/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | |
| Modificada | Media (4.3) | 1.2% | — | PHP Lite Calendar Express | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | PHP Lite Meeting Reserve | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5.1) | 1.6% | — | Jason Smith Cyboards PHP Lite | 10/3/2006 | 16/6/2026 | SQL injection vulnerability in CyBoards PHP Lite 1.25, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the parent parameter to (1) post.php and possibly (2) process_post.php. | |
| Modificada | Media (5.1) | 1.2% | — | Mirabilis ICQMirabilis ICQ Lite | 18/2/2006 | 16/6/2026 | ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified… | |
| Modificada | Media (5.1) | 1.2% | — | Mirabilis ICQMirabilis ICQ Lite | 18/2/2006 | 16/6/2026 | GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which… | |
| Modificada | Baja (2.6) | 1.6% | — | Reamday Enterprises Magic News Lite | 16/2/2006 | 16/6/2026 | preview.php en Reamday Enterprises Magic News Lite 1.2.3, cuando "register_globals" está habilitado, permite a atacantes remotos incluir ficheros arbitrarios mediante una URL en el parámetro php_script_path, que no es inicializado. | |
| Modificada | Baja (2.6) | 1.3% | — | Reamday Enterprises Magic News Lite | 16/2/2006 | 16/6/2026 | profile.php en Reamday Enterprises Magic News Lite 1.2.3, cuando "register_globals" está habilitado, permite a atacantes remotos modificar el comportamiento del programa, potencialmente evitando controles de autenticación, mediante la modificación de las variables (1) action, (2) passwd, (3) admin_password, (4)… | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Reamday Enterprises Magic Calendar Lite | 13/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | PHP Lite Calendar Express | 5/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (b) week.php, (c) month.php, and (d) year.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Phpyellowtm LitePhpyellowtm PRO | 5/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Td-systems Adc2000 NG PROTd-systems Adc2000 NG PRO Lite | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in adcbrowres.php in AD Center ADC2000 NG Pro 1.2 and NG Pro Lite allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) lang parameters. | |
| Modificada | Media (4.3) | 1.2% | — | Onlinetechtools.com Okbsys Lite | 27/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Online Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the q parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Onlinetechtools.com Oasys Lite | 27/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Onlinetechtools.com Owos Lite | 27/11/2005 | 16/6/2026 | SQL injection vulnerability in search.asp in Online Work Order Suite (OWOS) Lite Edition for ASP 3.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Litespeed Technologies Litespeed WEB Server | 20/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter. | |
| Modificada | Alta (7.5) | 4.7% | — | Oracle Database ServerOracle Database Server LiteOracle10gOracle8i+1 | 16/11/2005 | 16/6/2026 | Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Elite Forum | 1/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a topic, in which the reply contains a javascript: URL in an <img> tag. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Comersus Open Technologies Comersus Backoffice LiteComersus Open Technologies Comersus Backoffice Plus | 1/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2. | |
| Modificada | Alta (7.5) | 1.7% | — | Perception Liteweb | 9/6/2005 | 16/6/2026 | Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Qualiteam X-cart | 1/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode… | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Qualiteam X-cart | 1/6/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to… | |
| Modificada | Media (4.3) | 0.94% | — | Freestyle WikiFreestyle Wikilite | 31/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Baja (2.1) | 0.32% | — | Willings WebcamWillings Webcam Lite | 16/5/2005 | 16/6/2026 | Willings WebCam and WebCam Lite 2.8 and earlier stores the password in memory in plaintext, which allows local users to gain sensitive information. | |
| Modificada | Media (5) | 1.3% | — | Spidean At-liteSpidean Autotheme | 16/5/2005 | 16/6/2026 | Multiple unknown vulnerabilities in the Blocks module in Spidean AutoTheme 1.7 and AT-Lite for PostNuke have unknown impact. |