Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2886▲ 263 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%—Woltlab Burning Board LiteAI2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web script and HTML via the userid parameter.
ModificadaMedia (4.3)1.2%—Comersus Open Technologies Comersus Backoffice Lite2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_supportError.asp or (2) comersus_backofficelite_supportError.asp in BackOffice Lite 6.0 and 6.01 allow remote attackers to inject arbitrary web script or HTML via the error parameter.
ModificadaAlta (7.5)1.3%—Comersus Open Technologies Comersus Backoffice Lite2/5/200516/6/2026
SQL injection vulnerability in default.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to execute arbitrary SQL commands via the referer field in the HTTP header.
ModificadaAlta (7.2)0.73%—ADP Elite System MAX 90002/5/200516/6/2026
ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.
ModificadaAlta (7.5)1.6%—Comersus Open Technologies Comersus Backoffice Lite2/5/200516/6/2026
comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.
RechazadaSin puntuar—💥 ExploitLitecommerceAI6/4/20057/11/2023
Rejected reason: cart.php in LiteCommerce might allow remote attackers to obtain sensitive information via invalid (1) category_id or (2) product_id parameters. NOTE: this issue was originally claimed to be due to SQL injection, but the original researcher is known to be frequently inaccurate with respect to bug type…
ModificadaAlta (7.5)2.6%💥 ExploitStadtaus Download Center LiteAI7/3/200516/6/2026
PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.
ModificadaMedia (4.6)1.3%—Oracle Database Server Lite31/12/200416/6/2026
Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges.
ModificadaMedia (5)1.7%—Zanfi Solutions Zanfi CMS Lite31/12/200416/6/2026
PHP remote file inclusion vulnerability in index.php in Zanfi CMS lite 1.1 allows remote attackers to execute arbitrary PHP code via the inc parameter.
ModificadaMedia (5)2.3%—Zanfi Solutions Zanfi CMS Lite31/12/200416/6/2026
Zanfi CMS lite 1.1 allows remote attackers to obtain the full path of the web server via direct requests without required arguments to (1) adm_pages.php, (2) corr_pages.php, (3) del_block.php, (4) del_page.php, (5) footer.php, (6) home.php, and others.
ModificadaMedia (4.3)2.2%💥 ExploitExpinion.net News Manager Lite31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.
ModificadaMedia (5)1.4%—Cactusoft Cactushop Lite23/11/200416/6/2026
La función AddToMailingList en CactuSoft 5.0 Lite contiene una puerta trasera que permite a atacantes remotos borrar ficheros de su elección mediante una dirección de correo electrónico que comience con ||| (tres barras verticales).
ModificadaMedia (5)10%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6123/11/200416/6/2026
El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio.
ModificadaAlta (7.5)9.5%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo.
ModificadaMedia (5)7.2%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS.
ModificadaAlta (10)6.0%💥 ExploitQualiteam X-cart23/11/200416/6/2026
X-Cart 3.4.3 permite que atacantes remotos ejecuten comandos arbitrarios a través del argumento perl_binary en upgrade.php o general.php.
ModificadaMedia (5)6.9%💥 ExploitQualiteam X-cart23/11/200416/6/2026
X-Cart 3.4.3 permite que atacantes remotos obtengan información relevante mediante el parámetro de modo en los comandos phpinfo o perlinfo.
ModificadaMedia (5)1.5%—Qualiteam X-cart23/11/200416/6/2026
Vulnerabilidad de atravesamiento de directorios en X-Cart 3.4.3 permite que atacantes remotos vean ficheros arbitrarios mediante un argumento .. (punto punto) a shop_closed_file de auth.php
ModificadaAlta (7.2)2.6%💥 ExploitOracle Application ServerOracle Application Server PortalOracle Database Server LiteOracle8i+130/7/200416/6/2026
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
ModificadaAlta (7.5)1.7%💥 ExploitExpinion.net News Manager Lite20/3/200416/6/2026
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.
ModificadaAlta (7.5)2.9%💥 ExploitExpinion.net News Manager LiteAI20/3/200416/6/2026
News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.
ModificadaMedia (4.3)1.9%💥 ExploitSnapstream PVS LiteAI3/2/200416/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en SnapStream PVS LITE permite que atacantes remotos inyecten script web arbitrario o HTML mediante una petición GET que contiene un caracter comillas ("").
ModificadaMedia (5)1.9%—Perl CGI Lite31/12/200316/6/2026
The escape_dangerous_chars function in CGI::Lite 2.0 and earlier does not correctly remove special characters including (1) "\" (backslash), (2) "?", (3) "~" (tilde), (4) "^" (carat), (5) newline, or (6) carriage return, which could allow remote attackers to read or write arbitrary files, or execute arbitrary…
ModificadaAlta (10)7.0%—Perception Liteserve4/11/200316/6/2026
Buffer overflow in the log viewing interface in Perception LiteServe 1.25 through 2.2 allows remote attackers to execute arbitrary code via a GET request with a long file name.
ModificadaMedia (4.6)0.31%—ICQ INC Icqlite16/6/200316/6/2026
ICQLite 2003a crea el directorio ICQ Lite con privilegios de "Control Total" para usuarios interactivos, lo que permite que usuarios locales adquieran privilegios de otros usuarios reemplazando los ejecutables con programas dañinos.