Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.34% | — | IBM Advanced Settings UtilityIBM Bootable Media Creator | 19/12/2012 | 16/6/2026 | IBM Advanced Settings Utility (ASU) through 3.62 and 3.70 through 9.21 and Bootable Media Creator (BoMC) through 2.30 and 3.00 through 9.21 on Linux allow local users to overwrite arbitrary files via a symlink attack on a (1) temporary file or (2) log file. | |
| Modificada | Media (6.9) | 1.0% | 💥 Exploit | Roxio Easy Media Creator | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Roxio Easy Media Creator Home 9.0.136 allows local users to gain privileges via a Trojan horse homeutils9.dll file in the current working directory, as demonstrated by a directory that contains a .roxio, .c2d, or .gi file. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (4.3) | 1.1% | — | Netcreators Irfaq | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the "return url parameter." | |
| Modificada | Media (5.8) | 1.1% | — | Netcreators Irfaq | 14/2/2012 | 16/6/2026 | Open redirect vulnerability in the Modern FAQ (irfaq) extension 1.1.2 and other versions before 1.1.4 for TYPO3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL, probably in the "return url parameter." | |
| Modificada | Baja (2.1) | 0.36% | — | Evan Dandrea Usb-creator | 16/5/2011 | 16/6/2026 | usb-creator-helper in usb-creator before 0.2.28.3 does not enforce intended PolicyKit restrictions, which allows local users to perform arbitrary unmount operations via the UnmountFile method in a dbus-send command. | |
| Modificada | Media (6.9) | 0.35% | — | Nokia QT Creator | 4/10/2010 | 16/6/2026 | Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (4.3) | 6.4% | 💥 Exploit | JE Form Creator | 30/3/2010 | 16/6/2026 | Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE… | |
| Modificada | Media (5) | 1.6% | — | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Wscreator | 17/12/2009 | 16/6/2026 | SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the Email (aka username) parameter. | |
| Modificada | Alta (9.3) | 6.7% | — | Roxio CreatorRoxio Easy Media Creator | 3/12/2009 | 16/6/2026 | Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimensions. | |
| Modificada | Media (6.8) | 0.85% | 💥 Exploit | Cpecreator CP Creator | 23/9/2009 | 16/6/2026 | SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticket action. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Creative Mind Creator CMS | 19/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Comscripts WEB Server Creator WEB Portal | 30/3/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 3.6% | 💥 Exploit | Tizag Countdown Creator | 20/3/2009 | 16/6/2026 | Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Creative Mind Creator CMS | 1/10/2008 | 16/6/2026 | SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | M2scripts MY Space Scripts Poll Creator | 27/11/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in M2Scripts MySpace Scripts Poll Creator allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) intro, and (3) question parameters, and (4) unspecified answer parameters, in a create_new action. NOTE: some of these details… | |
| Modificada | Alta (7.5) | 1.1% | — | Advanced Website Creator | 30/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string. | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Webcreator | 14/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the moddir parameter to (1) content/load.inc.php, (2) config/load.inc.php, (3) http/load.inc.php, and unspecified other files. | |
| Modificada | Alta (10) | 8.8% | 💥 Exploit | Phppc PHP Poll Creator | 7/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PHP Poll Creator (phpPC) 1.04 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter to (1) poll.php, (2) poll_kommentar.php, and (3) poll_sm.php, different vectors and version than CVE-2005-1755. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | PHP Poll Creator | 7/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/functions.inc.php in PHP Poll Creator (phpPC) 1.04 allows remote attackers to execute arbitrary PHP code via a URL in the relativer_pfad parameter, a different vector and version than CVE-2005-1755. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (6.8) | 1.5% | — | Xenis.creator CMS | 8/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in xenis.creator CMS allow remote attackers to inject arbitrary web script or HTML via the (1) contid or (2) search parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | Xenis.creator CMS | 8/11/2006 | 16/6/2026 | SQL injection vulnerability in default.asp in Xenis.creator CMS allows remote attackers to execute arbitrary SQL commands via the contid parameter. | |
| Modificada | Baja (2.6) | 0.85% | — | Xenis.creator CMS | 8/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in xenis.creator CMS allows remote attackers to inject arbitrary web script or HTML via the nav parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |