Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1924 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Phpbb Group Phpbb Plus | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52 and earlier allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3) portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c parameter to index.php, or (7) the article… | |
| Modificada | Alta (7.2) | 0.37% | — | Webroot Software MY Firewall Plus | 10/1/2005 | 16/6/2026 | The Smc.exe process in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before invoking help, which allows local users to gain privileges. | |
| Modificada | Baja (2.1) | 0.47% | — | Broadcom Common ServicesBroadcom Unicenter Network AND Systems ManagementBroadcom Unicenter Serviceplus Service Desk | 31/12/2004 | 16/6/2026 | Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges. | |
| Modificada | Media (5) | 1.5% | — | Follett Software Webcollection Plus | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in s.dll in WebCollection Plus 5.00 allows remote attackers to view arbitrary files in c:\ via a full pathname in the d parameter. | |
| Modificada | Media (4.6) | 0.33% | — | Splus S-plusAI | 31/12/2003 | 16/6/2026 | S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6)… | |
| Modificada | Media (5) | 7.8% | 💥 Exploit | Coxco Support A-cartCoxco Support MetacartCoxco Support Midicart ASPCoxco Support Midicart ASP Maxi+3 | 11/4/2003 | 16/6/2026 | MidiCart almacena el fichero de base de datos midicart.mdb bajo la raíz de documentos web, lo que permite a atacantes remotos robar información sensible pidiendo la base de datos directamente. | |
| Modificada | Crítica (9.1) | 4.6% | 💥 Exploit | Midicart PHPMidicart PHP MaxiMidicart PHP Plus | 31/12/2002 | 16/6/2026 | MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to admin/upload.php or (2) access sensitive information via a direct request to admin/credit_card_info.php. | |
| Modificada | Media (5) | 1.2% | — | Uninet Statsplus | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in stat.pl in StatsPlus 1.25 allows remote attackers to inject arbitrary web script or HTML via (1) HTTP_USER_AGENT or (2) HTTP_REFERER, which is written to stats.html and executed in client browsers. | |
| Modificada | Media (5) | 4.2% | — | Microsoft Windows 98 Plus PackMicrosoft Windows MEMicrosoft Windows XP | 11/10/2002 | 16/6/2026 | La característica de Carpetas Comprimidas en Microsoft Windows 98 con el paquete Plus!, Windows Me, y Windows XP no comprueba adecuadamente la carpeta de destino durante la descompresión de ficheros ZIP, lo que permite a atacantes remotos poner un fichero ejecutable en una lugar conocido en el sistema del usuario,… | |
| Modificada | Alta (7.5) | 43% | — | Allume Systems Division Stuffit ExpanderIBM Lotus NotesVerity Keyview Viewing SDKWinzip+3 | 10/10/2002 | 16/6/2026 | Desbordamiento de búfer en la capacidad ZIP de múltiples productos permite a atacantes remotos causar una denegación de servicio o ejecutar código arbitrario mediante ficheros ZIP que contienen nombres de ficheros largos, incluyendo Microsoft Windows 98 con el paquete Plus! Windows XP Windows Me Lotus Notes R4 a R6… | |
| Modificada | Alta (7.5) | 2.0% | — | Realnetworks Realjukebox 2Realnetworks Realjukebox 2 PlusRealnetworks Realone Player | 4/10/2002 | 16/6/2026 | RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by… | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Realnetworks Realjukebox 2Realnetworks Realjukebox 2 PlusRealnetworks Realone Player | 4/10/2002 | 16/6/2026 | Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image. | |
| Modificada | Alta (7.5) | 2.4% | — | Mutasem Abudahab CsvformMutasem Abudahab Csvform Plus | 11/12/2001 | 16/6/2026 | csvform.pl 0.1 permite a atacantes remotos la ejecución de comandos arbitrarios mediante el uso de metacaracteres en el fichero dado como parámetro. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Ibill Internet Billing Company Processing Plus | 6/12/2001 | 16/6/2026 | ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing. | |
| Modificada | Alta (7.5) | 2.1% | — | Kabotie Software Technologies Shopplus Cart | 5/9/2001 | 16/6/2026 | shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | QPC Software QVT NETQPC Software QVT Term Plus | 2/7/2001 | 16/6/2026 | Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password. | |
| Modificada | Media (4.6) | 0.33% | — | Rediplus | 27/6/2001 | 16/6/2026 | REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts. | |
| Modificada | Baja (2.1) | 8.9% | — | Microsoft Plus | 3/5/2001 | 16/6/2026 | The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password information to a file, which allows local users to recover the passwords and read the compressed folders. | |
| Modificada | Media (5) | 9.7% | 💥 Exploit | Netcplus Browsegate | 19/12/2000 | 23/9/2026 | BrowseGate 2.80 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar comandos arbitrarios a través de encabezados MIME largos de Authorization o Referer en la solicitud HTTP. | |
| Modificada | Baja (3.6) | 0.74% | 💥 Exploit | Plus Technologies Lpplus | 14/11/2000 | 16/6/2026 | LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file. | |
| Modificada | Baja (2.1) | 0.42% | — | Plus Technologies Lpplus | 14/11/2000 | 16/6/2026 | LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services. | |
| Modificada | Baja (2.1) | 0.87% | 💥 Exploit | Plus Technologies Lpplus | 14/11/2000 | 16/6/2026 | The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | Powerscripts Plusmail | 11/1/2000 | 16/6/2026 | PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | QPC Software QVT NETQPC Software QVT Term Plus | 10/11/1999 | 16/6/2026 | Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password. |