Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3090▲ 519 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1973 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.9% | — | Wordpress | 31/5/2006 | 16/6/2026 | vars.php in WordPress 2.0.2, possibly when running on Mac OS X, allows remote attackers to spoof their IP address via a PC_REMOTE_ADDR HTTP header, which vars.php uses to redefine $_SERVER['REMOTE_ADDR']. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Wordpress | 30/5/2006 | 16/6/2026 | Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2)… | |
| Modificada | Media (6.8) | 2.0% | — | Wordpress | 17/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the paging links functionality in template-functions-links.php in Wordpress 1.5.2, and possibly other versions before 2.0.1, allows remote attackers to inject arbitrary web script or HTML to Internet Explorer users via the request URI ($_SERVER['REQUEST_URI']). | |
| Modificada | Media (4.9) | 0.33% | — | Counterpane Password Safe | 24/3/2006 | 16/6/2026 | PasswordSafe 3.0 beta, when running on Windows before XP, uses a weak random number generator (C++ rand function) during generation of the database encryption key, which makes it easier for attackers to decrypt the database and steal passwords by generating keys for all possible rand() seed values and conducting a… | |
| Modificada | Media (4.3) | 1.7% | — | Wordpress | 19/3/2006 | 16/6/2026 | Multiple "unannounced" cross-site scripting (XSS) vulnerabilities in WordPress before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Alta (7.5) | 3.0% | — | Wordpress | 6/3/2006 | 16/6/2026 | Vulnerabilidad de inyección de SQL en WordPress 1.5.2, y posiblemente otras versiones anteriores a 2.0, permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el campo "User-Agent" en la cabecera HTTP de un comentario. | |
| Modificada | Media (4.3) | 3.1% | — | Wordpress | 3/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the "post comment" functionality of WordPress 2.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) website, and (3) comment parameters. | |
| Modificada | Media (5) | 3.3% | — | Wordpress | 3/3/2006 | 16/6/2026 | WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-filters.php, (2) template-loader.php, (3) rss-functions.php, (4) locale.php, (5) wp-db.php, and (6) kses.php in the wp-includes/ directory; and (7) edit-form-advanced.php, (8) admin-functions.php,… | |
| Modificada | Baja (2.6) | 6.4% | — | Microsoft Word | 28/2/2006 | 16/6/2026 | Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz. | |
| Modificada | Media (5.1) | 4.0% | — | Njstar Chinese Word ProcessorNjstar Japanese Word Processor | 21/2/2006 | 16/6/2026 | Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents. | |
| Modificada | Baja (2.6) | 4.8% | 💥 Exploit | Wordpress | 16/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WordPress 2.0.0 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes such as (1) onfocus and (2) onblur in the "author's website" field. NOTE: followup comments to the researcher's web log suggest that this issue is only exploitable by the… | |
| Modificada | Media (4.3) | 1.5% | — | Wordcircle | 13/1/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fields in unspecified scripts. | |
| Modificada | Media (5.1) | 1.9% | — | Wordcircle | 13/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Wordcircle 2.17 allow remote attackers to (1) execute arbitrary SQL commands and bypass authentication via the password field in the login action to index.php (involving v_login.php and s_user.php) and (2) have other unknown impact via certain other fields in unspecified… | |
| Modificada | Baja (1.9) | 0.34% | — | Antiword | 31/12/2005 | 16/6/2026 | The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on temporary (a) output and (b) error files. | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Alta (10) | 1.4% | — | Pear Text Password | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Media (5) | 3.3% | — | Wordpress | 21/12/2005 | 16/6/2026 | WordPress before 1.5.2 allows remote attackers to obtain sensitive information via a direct request to (1) wp-includes/vars.php, (2) wp-content/plugins/hello.php, (3) wp-admin/upgrade-functions.php, (4) wp-admin/edit-form.php, (5) wp-settings.php, and (6) wp-admin/edit-form-comment.php, which leaks the path in an… | |
| Modificada | Media (4.3) | 1.2% | — | Web4future Keyword Frequency Counter | 6/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cgi in Web4Future KeyWord Frequency Counter 1.0 allows remote attackers to inject arbitrary web script or HTML via the "remote URL." | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpwordpress PHP News AND Article Manager | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action. | |
| Modificada | Media (4.6) | 0.21% | — | Counterpane Passwordsafe | 24/11/2005 | 16/6/2026 | CounterPane PasswordSafe 1.x y 2.x permite a usuarios locales probar posibles claves de cifrado contra un subconjunto de los datos de claves almacenados sin realizar una función de derivación de clave (KDF) más cara, lo que reduce el tiempo de búsqueda en ataques de fuerza bruta. | |
| Modificada | Media (5.1) | 4.1% | — | Abisource Community Abiword | 23/10/2005 | 16/6/2026 | Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions… | |
| Modificada | Alta (7.5) | 4.6% | — | Abisource Community Abiword | 28/9/2005 | 16/6/2026 | Stack-based buffer overflow in AbiWord before 2.2.10 allows attackers to execute arbitrary code via the RTF import mechanism. | |
| Modificada | Alta (7.5) | 39% | 💥 Exploit | Wordpress | 17/8/2005 | 16/6/2026 | Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie. |