Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3082▲ 502 respecto a la semana anterior
Críticas / altas1460▲ 59 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1973 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 26% | — | Microsoft Word | 12/7/2005 | 16/6/2026 | Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information. | |
| Modificada | Alta (7.5) | 9.3% | 💥 Exploit | Wordpress | 5/7/2005 | 16/6/2026 | SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file. | |
| Modificada | Media (5) | 2.9% | — | Wordpress | 5/7/2005 | 16/6/2026 | WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an error message. NOTE: vector [1] was later reported to also affect… | |
| Modificada | Media (5) | 2.6% | — | Wordpress | 5/7/2005 | 16/6/2026 | wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use. | |
| Modificada | Media (4.3) | 2.6% | — | Wordpress | 5/7/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter. | |
| Modificada | Alta (7.5) | 3.1% | — | Wordpress | 1/6/2005 | 16/6/2026 | SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php. | |
| Modificada | Baja (2.6) | 15% | — | Microsoft Word | 20/5/2005 | 16/6/2026 | Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file. | |
| Modificada | Alta (7.5) | 2.3% | — | Wordpress | 20/5/2005 | 16/6/2026 | SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. | |
| Modificada | Media (5.3) | 1.9% | — | Wordpress | 20/5/2005 | 16/6/2026 | Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message. | |
| Modificada | Media (6.8) | 2.9% | — | Wordpress | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post. | |
| Modificada | Alta (7.5) | 2.3% | — | Crosswire Bible Society Sword | 2/5/2005 | 16/6/2026 | diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Media (5.1) | 15% | — | Microsoft Word | 2/5/2005 | 16/6/2026 | Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document. | |
| Modificada | Baja (2.1) | 0.37% | — | Citrix Metaframe Password Manager | 2/5/2005 | 16/6/2026 | Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy. | |
| Modificada | Alta (10) | 32% | — | Microsoft Word | 9/2/2005 | 16/6/2026 | Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds… | |
| Modificada | Alta (7.5) | 27% | — | Microsoft OfficeMicrosoft PowerpointMicrosoft ProjectMicrosoft Visio+2 | 8/2/2005 | 16/6/2026 | Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames. | |
| Modificada | Alta (7.2) | 0.38% | — | Changepassword | 10/1/2005 | 16/6/2026 | changepassword.cgi en ChangePassword 0.8, cuando se instala con setuid, permite a usuarios locales ejecutar código de su elección modifcando la variable de entorno PATH para que apunte a un programa "make" malicioso. | |
| Modificada | Media (4.3) | 6.5% | 💥 Exploit | Wordpress | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Wordpress 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) redirect_to, text, popupurl, or popuptitle parameters to wp-login.php, (2) redirect_url parameter to admin-header.php, (3) popuptitle, popupurl, content, or post_title… | |
| Modificada | Media (5) | 11% | 💥 Exploit | Wordpress | 31/12/2004 | 16/6/2026 | CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the text parameter. | |
| Modificada | Baja (2.1) | 0.36% | — | Citrix Metaframe Password Manager | 31/12/2004 | 16/6/2026 | The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. | |
| Modificada | Alta (7.5) | 42% | — | Microsoft FrontpageMicrosoft OfficeMicrosoft PublisherMicrosoft Word+1 | 28/9/2004 | 16/6/2026 | Desbordamiento de búfer en el convertidor de Microsoft WordPerfect 5.x en Office 2000, Office XP, Offiece 2003 y las suites Works 2001 a 2004 permite a atacantes remotos ejecutar código de su elección mediante un documento o un sitio web malicioso. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria. | |
| Modificada | Media (4.3) | 1.3% | — | WEB Animations Password Protect | 31/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) index.asp, (2) ChangePassword.asp, (3) users_list.asp, (4) and users_add.asp in Password Protect allows remote attackers to inject arbitrary web script or HTML via the ShowMsg parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | WEB Animations Password Protect | 30/8/2004 | 16/6/2026 | SQL injection vulnerability in Password Protect allows remote attackers to execute arbitrary SQL statements and bypass authentication via (1) admin or Pass parameter to index_next.asp, (2) LoginId, OPass, or NPass to CPassChangePassword.asp, (3) users_edit.asp, or (4) users_add.asp. | |
| Modificada | Alta (10) | 8.4% | — | Abisource Community AbiwordWvware | 6/8/2004 | 16/6/2026 | Desbordamiento de búfer en la función wvHandleDateTimePicture en la librería wv (wvWare) 0.7.4 a 0.7.6 y 1.0.0 permite a atacantes remotos ejecutar código de su elección mediante un documento con un campo DateTime largo. | |
| Modificada | Media (5) | 1.3% | — | Coffeecup Software Coffeecup Password Wizard | 31/12/2003 | 16/6/2026 | CoffeeCup Software Password Wizard 4.0 stores sensitive information such as usernames and passwords in a .apw file under the web document root with insufficient access control, which allows remote attackers to obtain that information via a direct request for the file. |