Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1918 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 1.5% | 💥 Exploit | Smartwin Technology Cyberoffice Warehouse Builder | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Smartwin Technology Cyberoffice Warehouse Builder | 4/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Mysmartbb | 29/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) username parameters. | |
| Modificada | Alta (7.5) | 1.3% | — | Mysmartbb | 29/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) username parameters. | |
| Modificada | Baja (2.6) | 2.2% | 💥 Exploit | Smarter Scripts Intellilink PRO | 20/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgotpass parameters in edit.cgi. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Smartisoft Phplistpro | 12/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter. NOTE: this issue was later reported to affect 2.01 as well. | |
| Modificada | Media (5) | 1.9% | — | Smart Technologies Synchroneyes | 6/4/2006 | 16/6/2026 | SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker's machine and read a value that is used as a parameter to malloc. | |
| Modificada | Alta (7.8) | 2.2% | — | Smart Technologies Synchroneyes | 6/4/2006 | 16/6/2026 | An unspecified "logical programming mistake" in SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service via a large packet to the Teacher discovery port (UDP port 5496), which causes a thread to terminate and prevents communications on that port. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Smartblog | 7/3/2006 | 16/6/2026 | PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Orbitscripts Smartppc PRO | 26/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SmartPPC Pro allow remote attackers to inject arbitrary web script or HTML via the username parameter in (1) directory.php, (2) frames.php, and (3) search.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Smartlist | 3/5/2005 | 16/6/2026 | The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned. | |
| Modificada | Alta (7.5) | 1.5% | — | Smarty | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code. | |
| Modificada | Media (4.3) | 1.3% | — | Phpbb Group PhpbbSmartor Photo Album | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpbb Group PhpbbSmartor Photo Album | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters. | |
| Modificada | Baja (2.1) | 0.83% | 💥 Exploit | Smartstuff Foolproof Security | 31/12/2004 | 16/6/2026 | Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key. | |
| Modificada | Media (4) | 1.1% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability. | |
| Modificada | Alta (7.8) | 1.8% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous open connections to TCP port 25. | |
| Modificada | Media (4.3) | 1.4% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to inject arbitrary web script or HTML via Javascript to the "check spelling" feature in the compose area. | |
| Modificada | Media (4.3) | 1.3% | — | Gosmart Message Board | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp. | |
| Modificada | Alta (7.5) | 1.3% | — | Gosmart Message Board | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp. | |
| Modificada | Media (5) | 1.5% | — | Smartwebby Smart Guest Book | 31/12/2004 | 16/6/2026 | SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account. | |
| Modificada | Media (5) | 1.9% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to read arbitrary files via the filename parameter. | |
| Modificada | Media (5) | 1.9% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a long txtusername parameter, possibly due to a buffer overflow. | |
| Modificada | Alta (7.5) | 2.8% | — | Baalsystems Baal Smart Forms | 31/12/2004 | 16/6/2026 | Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Securecomputing Smartether Ss6215s Switch | 26/4/2004 | 16/6/2026 | Samsung SmartEther SS6215S switch, and possibly other Samsung switches, allows remote attackers and local users to gain administrative access by providing the admin username followed by a password that is the maximum allowed length, then pressing the enter key after the resulting error message. |