Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1962 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Solmetra Spaw Editor22/8/200616/6/2026
Múltiples vulnerabilidades de inclusión remota de archivo en PHP en SOLMETRA SPAW Editor 1.0.6 y 1.0.7 permiten a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro spaw_dir en ficheros de dialogs/ que incluyen (1) a.php, (2) collorpicker.php, (3) img.php, (4) img_library.php, (5)…
ModificadaAlta (9)2.9%—Symantec Veritas Netbackup Puredisk Remote Office Edition18/8/200616/6/2026
Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 anterior a MP1 16/08/2006 permite a atacantes remotos evitar la autenticación y obtener privilegios mediante vectores de ataque desconocidos en la interfaz de administración.
ModificadaAlta (7.5)3.7%💥 ExploitZonemetrics Zonex Publishers Gold Edition9/8/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en includes/usercp_register.php de ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 y versiones anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro phpbb_root_path.
ModificadaAlta (7.5)2.5%💥 ExploitWonderedit PRO CMS7/7/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en WonderEdit Pro CMS permite a atacantes remotos ejecutar código PHP de su elección mediante el parámetro config[template_path] en user_bottom.php, usado en múltiples plantillas, entre ellas (1) rwb (template/rwb/user_bottom.php), (2) gwb…
ModificadaBaja (2.6)1.3%—Bnbt EasytrackerBnbt Trinedit27/6/200616/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en index.html de BNBT TrinEdit y EasyTracker v7.7r3.2004.10.27 y versiones anteriores. Permiten a usuarios remotos inyectar codigo de script web o código HTML de su elección a través de los parámetros (1) filter o (2) sort.
ModificadaBaja (2.6)1.5%—Jaguarsoft Jaguaredit24/6/200616/6/2026
JaguarEditControl (JEdit) ActiveX Control v1.1.0.20 y anteriores permiten a atacantes remotos obtener información sensible, como el nombre de usuario, dirección MAC y dirección IP, fijando el campo text a ciertos valores como a 2404 o 2790, entonces leyendo la información desde el campo .JText.
ModificadaAlta (7.5)3.4%💥 ExploitNukedit1/6/200616/6/2026
utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.
ModificadaMedia (4.3)1.4%—Neocrome Seditio30/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in Neocrome Land Down Under (LDU) in Neocrome Seditio 102 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer field.
ModificadaMedia (5)2.4%—Fckeditor22/5/200616/6/2026
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658.
ModificadaAlta (7.5)1.5%—Activecampaign 1-2-allActivecampaign GeneralActivecampaign IsalientActivecampaign Knowledgebuilder+23/3/200616/6/2026
PHP remote file inclusion vulnerability in index.php in one or more ActiveCampaign products, possibly SupportTrio, allows remote attackers to include and execute arbitrary files via the page parameter.
ModificadaMedia (6.4)1.7%—Fckeditor28/2/200616/6/2026
Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.
ModificadaMedia (5)6.9%💥 ExploitFckeditor13/2/200616/6/2026
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
ModificadaMedia (4.9)0.46%—Tashcom Aspedit31/12/200516/6/2026
Tashcom ASPEdit 2.9 stores the administration password (aka the FTP password) in cleartext in the registry, which might allow local users to view the password.
ModificadaMedia (4.3)1.3%—Citypost Simple Image Editor31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter.
ModificadaAlta (7.8)12%💥 ExploitApple SafariApple TexteditApple MAC OS XApple MAC OS X Server22/12/200516/6/2026
The khtml::RenderTableSection::ensureRows function in KHTMLParser in Apple Mac OS X 10.4.3 and earlier, as used by Safari and TextEdit, allows remote attackers to cause a denial of service (memory consumption and application crash) via HTML files with a large ROWSPAN attribute in a TD tag.
ModificadaMedia (6.8)2.0%💥 ExploitOpenedit INC Openedit22/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page parameters.
ModificadaAlta (7.5)1.5%—Dev-editor20/12/200516/6/2026
Dev-Editor 3.0 allows remote attackers to access any directory outside the web root whose name is a substring of the web root directory name.
ModificadaAlta (7.5)1.3%💥 ExploitWeb4future Ecommerce Enterprise EditionAI6/12/200516/6/2026
Multiple SQL injection vulnerabilities in Web4Future eCommerce Enterprise Edition 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) prod, and (2) brid parameters to (a) view.php; the (3) the bid parameter to (b) viewbrands.php; and the (4) grp and (5) cat parameters to index.php.
ModificadaMedia (4.6)0.33%—Stanis Python Editor23/10/200516/6/2026
Stani's Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files.
ModificadaAlta (7.5)2.1%—Dtlink Areaedit23/8/200516/6/2026
aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable).
ModificadaAlta (7.5)2.3%—Community Link PRO WEB Editor5/7/200516/6/2026
login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.
ModificadaBaja (2.6)7.7%💥 ExploitGnome Gedit20/5/200516/6/2026
Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be…
ModificadaMedia (5.1)2.8%—HT Editor14/5/200516/6/2026
Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.
ModificadaMedia (5.1)2.2%—HT Editor14/5/200516/6/2026
Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.
ModificadaMedia (5)4.6%💥 ExploitFckeditor28/2/200516/6/2026
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.