Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1918 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.8)1.5%💥 ExploitSmartwin Technology Cyberoffice Warehouse Builder4/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2…
ModificadaAlta (7.5)2.7%💥 ExploitSmartwin Technology Cyberoffice Warehouse Builder4/5/200616/6/2026
Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.
ModificadaMedia (4.3)1.7%💥 ExploitMysmartbb29/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) username parameters.
ModificadaAlta (7.5)1.3%—Mysmartbb29/4/200616/6/2026
Multiple SQL injection vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) username parameters.
ModificadaBaja (2.6)2.2%💥 ExploitSmarter Scripts Intellilink PRO20/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgotpass parameters in edit.cgi.
ModificadaAlta (7.5)8.1%💥 ExploitSmartisoft Phplistpro12/4/200616/6/2026
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter. NOTE: this issue was later reported to affect 2.01 as well.
ModificadaMedia (5)1.9%—Smart Technologies Synchroneyes6/4/200616/6/2026
SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker's machine and read a value that is used as a parameter to malloc.
ModificadaAlta (7.8)2.2%—Smart Technologies Synchroneyes6/4/200616/6/2026
An unspecified "logical programming mistake" in SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service via a large packet to the Teacher discovery port (UDP port 5496), which causes a thread to terminate and prevents communications on that port.
ModificadaAlta (7.5)2.6%💥 ExploitSmartblog7/3/200616/6/2026
PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.
ModificadaMedia (4.3)1.8%—Orbitscripts Smartppc PRO26/11/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SmartPPC Pro allow remote attackers to inject arbitrary web script or HTML via the username parameter in (1) directory.php, (2) frames.php, and (3) search.php.
ModificadaAlta (7.5)1.2%—Smartlist3/5/200516/6/2026
The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.
ModificadaAlta (7.5)1.5%—Smarty2/5/200516/6/2026
Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.
ModificadaMedia (4.3)1.3%—Phpbb Group PhpbbSmartor Photo Album2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php.
ModificadaAlta (7.5)1.3%—Phpbb Group PhpbbSmartor Photo Album2/5/200516/6/2026
Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters.
ModificadaBaja (2.1)0.83%💥 ExploitSmartstuff Foolproof Security31/12/200416/6/2026
Riverdeep FoolProof Security 3.9.x on Windows 98 and Windows ME uses weak cryptography (arithmetic and XOR operations) to relate the Control password to the Administrator password, which allows local users to calculate the Administrator password if they know the Control password and password recovery key.
ModificadaMedia (4)1.1%—Smartertools Smartermail31/12/200416/6/2026
frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability.
ModificadaAlta (7.8)1.8%—Smartertools Smartermail31/12/200416/6/2026
SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous open connections to TCP port 25.
ModificadaMedia (4.3)1.4%—Smartertools Smartermail31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to inject arbitrary web script or HTML via Javascript to the "check spelling" feature in the compose area.
ModificadaMedia (4.3)1.3%—Gosmart Message Board31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in GoSmart Message Board allows remote attackers to execute inject web script or HTML via the (1) Category parameter to Forum.asp or (2) MainMessageID parameter to ReplyToQuestion.asp.
ModificadaAlta (7.5)1.3%—Gosmart Message Board31/12/200416/6/2026
SQL injection vulnerability in GoSmart Message Board allows remote attackers to execute arbitrary SQL code via the (1) QuestionNumber and Category parameters to Forum.asp or (2) Username and Password parameter to Login_Exec.asp.
ModificadaMedia (5)1.5%—Smartwebby Smart Guest Book31/12/200416/6/2026
SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account.
ModificadaMedia (5)1.9%—Smartertools Smartermail31/12/200416/6/2026
Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to read arbitrary files via the filename parameter.
ModificadaMedia (5)1.9%—Smartertools Smartermail31/12/200416/6/2026
login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a long txtusername parameter, possibly due to a buffer overflow.
ModificadaAlta (7.5)2.8%—Baalsystems Baal Smart Forms31/12/200416/6/2026
Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.
ModificadaAlta (7.5)1.5%—Securecomputing Smartether Ss6215s Switch26/4/200416/6/2026
Samsung SmartEther SS6215S switch, and possibly other Samsung switches, allows remote attackers and local users to gain administrative access by providing the admin username followed by a password that is the maximum allowed length, then pressing the enter key after the resulting error message.