Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1962 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Solmetra Spaw Editor | 22/8/2006 | 16/6/2026 | Múltiples vulnerabilidades de inclusión remota de archivo en PHP en SOLMETRA SPAW Editor 1.0.6 y 1.0.7 permiten a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro spaw_dir en ficheros de dialogs/ que incluyen (1) a.php, (2) collorpicker.php, (3) img.php, (4) img_library.php, (5)… | |
| Modificada | Alta (9) | 2.9% | — | Symantec Veritas Netbackup Puredisk Remote Office Edition | 18/8/2006 | 16/6/2026 | Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 anterior a MP1 16/08/2006 permite a atacantes remotos evitar la autenticación y obtener privilegios mediante vectores de ataque desconocidos en la interfaz de administración. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Zonemetrics Zonex Publishers Gold Edition | 9/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en includes/usercp_register.php de ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 y versiones anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro phpbb_root_path. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Wonderedit PRO CMS | 7/7/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en WonderEdit Pro CMS permite a atacantes remotos ejecutar código PHP de su elección mediante el parámetro config[template_path] en user_bottom.php, usado en múltiples plantillas, entre ellas (1) rwb (template/rwb/user_bottom.php), (2) gwb… | |
| Modificada | Baja (2.6) | 1.3% | — | Bnbt EasytrackerBnbt Trinedit | 27/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en index.html de BNBT TrinEdit y EasyTracker v7.7r3.2004.10.27 y versiones anteriores. Permiten a usuarios remotos inyectar codigo de script web o código HTML de su elección a través de los parámetros (1) filter o (2) sort. | |
| Modificada | Baja (2.6) | 1.5% | — | Jaguarsoft Jaguaredit | 24/6/2006 | 16/6/2026 | JaguarEditControl (JEdit) ActiveX Control v1.1.0.20 y anteriores permiten a atacantes remotos obtener información sensible, como el nombre de usuario, dirección MAC y dirección IP, fijando el campo text a ciertos valores como a 2404 o 2790, entonces leyendo la información desde el campo .JText. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Nukedit | 1/6/2006 | 16/6/2026 | utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action. | |
| Modificada | Media (4.3) | 1.4% | — | Neocrome Seditio | 30/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer field. | |
| Modificada | Media (5) | 2.4% | — | Fckeditor | 22/5/2006 | 16/6/2026 | editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658. | |
| Modificada | Alta (7.5) | 1.5% | — | Activecampaign 1-2-allActivecampaign GeneralActivecampaign IsalientActivecampaign Knowledgebuilder+2 | 3/3/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter. | |
| Modificada | Media (6.4) | 1.7% | — | Fckeditor | 28/2/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder. | |
| Modificada | Media (5) | 6.9% | 💥 Exploit | Fckeditor | 13/2/2006 | 16/6/2026 | Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt. | |
| Modificada | Media (4.9) | 0.46% | — | Tashcom Aspedit | 31/12/2005 | 16/6/2026 | Tashcom ASPEdit 2.9 stores the administration password (aka the FTP password) in cleartext in the registry, which might allow local users to view the password. | |
| Modificada | Media (4.3) | 1.3% | — | Citypost Simple Image Editor | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter. | |
| Modificada | Alta (7.8) | 12% | 💥 Exploit | Apple SafariApple TexteditApple MAC OS XApple MAC OS X Server | 22/12/2005 | 16/6/2026 | The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Openedit INC Openedit | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Dev-editor | 20/12/2005 | 16/6/2026 | Dev-Editor 3.0 allows remote attackers to access any directory outside the web root whose name is a substring of the web root directory name. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Web4future Ecommerce Enterprise EditionAI | 6/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php. | |
| Modificada | Media (4.6) | 0.33% | — | Stanis Python Editor | 23/10/2005 | 16/6/2026 | Stani's Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files. | |
| Modificada | Alta (7.5) | 2.1% | — | Dtlink Areaedit | 23/8/2005 | 16/6/2026 | aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable). | |
| Modificada | Alta (7.5) | 2.3% | — | Community Link PRO WEB Editor | 5/7/2005 | 16/6/2026 | login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter. | |
| Modificada | Baja (2.6) | 7.7% | 💥 Exploit | Gnome Gedit | 20/5/2005 | 16/6/2026 | Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be… | |
| Modificada | Media (5.1) | 2.8% | — | HT Editor | 14/5/2005 | 16/6/2026 | Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file. | |
| Modificada | Media (5.1) | 2.2% | — | HT Editor | 14/5/2005 | 16/6/2026 | Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow. | |
| Modificada | Media (5) | 4.6% | 💥 Exploit | Fckeditor | 28/2/2005 | 16/6/2026 | Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files. |