Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2886▲ 263 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Woltlab Burning Board LiteAI | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web script and HTML via the userid parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Comersus Open Technologies Comersus Backoffice Lite | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Comersus Open Technologies Comersus Backoffice Lite | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header. | |
| Modificada | Alta (7.2) | 0.73% | — | ADP Elite System MAX 9000 | 2/5/2005 | 16/6/2026 | ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory. | |
| Modificada | Alta (7.5) | 1.6% | — | Comersus Open Technologies Comersus Backoffice Lite | 2/5/2005 | 16/6/2026 | comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program. | |
| Rechazada | Sin puntuar | — | 💥 Exploit | LitecommerceAI | 6/4/2005 | 7/11/2023 | Rejected reason: cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters. NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Stadtaus Download Center LiteAI | 7/3/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (4.6) | 1.3% | — | Oracle Database Server Lite | 31/12/2004 | 16/6/2026 | Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges. | |
| Modificada | Media (5) | 1.7% | — | Zanfi Solutions Zanfi CMS Lite | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Zanfi CMS lite 1.1 allows remote attackers to execute arbitrary PHP code via the inc parameter. | |
| Modificada | Media (5) | 2.3% | — | Zanfi Solutions Zanfi CMS Lite | 31/12/2004 | 16/6/2026 | Zanfi CMS lite 1.1 allows remote attackers to obtain the full path of the web server via direct requests without required arguments to (1) adm_pages.php, (2) corr_pages.php, (3) del_block.php, (4) del_page.php, (5) footer.php, (6) home.php, and others. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Expinion.net News Manager Lite | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp. | |
| Modificada | Media (5) | 1.4% | — | Cactusoft Cactushop Lite | 23/11/2004 | 16/6/2026 | La función AddToMailingList en CactuSoft 5.0 Lite contiene una puerta trasera que permite a atacantes remotos borrar ficheros de su elección mediante una dirección de correo electrónico que comience con ||| (tres barras verticales). | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. | |
| Modificada | Alta (10) | 6.0% | 💥 Exploit | Qualiteam X-cart | 23/11/2004 | 16/6/2026 | X-Cart 3.4.3 permite que atacantes remotos ejecuten comandos arbitrarios a través del argumento perl_binary en upgrade.php o general.php. | |
| Modificada | Media (5) | 6.9% | 💥 Exploit | Qualiteam X-cart | 23/11/2004 | 16/6/2026 | X-Cart 3.4.3 permite que atacantes remotos obtengan información relevante mediante el parámetro de modo en los comandos phpinfo o perlinfo. | |
| Modificada | Media (5) | 1.5% | — | Qualiteam X-cart | 23/11/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en X-Cart 3.4.3 permite que atacantes remotos vean ficheros arbitrarios mediante un argumento .. (punto punto) a shop_closed_file de auth.php | |
| Modificada | Alta (7.2) | 2.6% | 💥 Exploit | Oracle Application ServerOracle Application Server PortalOracle Database Server LiteOracle8i+1 | 30/7/2004 | 16/6/2026 | The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Expinion.net News Manager Lite | 20/3/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Expinion.net News Manager LiteAI | 20/3/2004 | 16/6/2026 | News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Snapstream PVS LiteAI | 3/2/2004 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en SnapStream PVS LITE permite que atacantes remotos inyecten script web arbitrario o HTML mediante una petición GET que contiene un caracter comillas (""). | |
| Modificada | Media (5) | 1.9% | — | Perl CGI Lite | 31/12/2003 | 16/6/2026 | The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary… | |
| Modificada | Alta (10) | 7.0% | — | Perception Liteserve | 4/11/2003 | 16/6/2026 | Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name. | |
| Modificada | Media (4.6) | 0.31% | — | ICQ INC Icqlite | 16/6/2003 | 16/6/2026 | ICQLite 2003a crea el directorio ICQ Lite con privilegios de "Control Total" para usuarios interactivos, lo que permite que usuarios locales adquieran privilegios de otros usuarios reemplazando los ejecutables con programas dañinos. |