Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▲ 220 respecto a la semana anterior
Críticas / altas1330▼ 101 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | Mantis | 27/10/2005 | 16/6/2026 | Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users. | |
| Modificada | Media (4.3) | 1.2% | — | Mantis | 27/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php. | |
| Modificada | Alta (7.5) | 1.9% | — | Mantis | 27/10/2005 | 16/6/2026 | SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Alta (7.5) | 6.6% | — | Mantis | 27/10/2005 | 16/6/2026 | PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Mantis | 28/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in bug_actiongroup_page.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the summary of the bug, which is not quoted when view_all_bug_page.php is used to delete the bug, as identified by bug#0006002, a different… | |
| Modificada | Media (4.3) | 1.2% | — | Mantis | 28/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, as identified by bug#0005751 "thraxisp". | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | MantisDebian LinuxGentoo Linux | 28/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090. | |
| Modificada | Alta (7.5) | 1.6% | — | Mantis | 24/8/2005 | 16/6/2026 | core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956. | |
| Modificada | Media (5) | 1.3% | — | Mantis | 31/12/2004 | 16/6/2026 | Mantis before 20041016 provides a complete Issue History (Bug History) in the web interface regardless of view_history_threshold, which allows remote attackers to obtain sensitive information (private bug details) by visiting a bug's web page. | |
| Modificada | Alta (7.5) | 1.7% | — | Mantis | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in Mantis 0.19.0a allows remote attackers to execute arbitrary PHP code by modifying the (1) t_core_path parameter to bug_api.php or (2) t_core_dir parameter to relationship_api.php to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (4.3) | 1.4% | — | Mantis | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mantis bugtracker allows remote attackers to inject arbitrary web script or HTML via (1) the return parameter to login_page.php, (2) e-mail field in signup.php, (3) action parameter to login_select_proj_page.php, or (4) hide_status parameter to view_all_set.php. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Mantis | 20/8/2004 | 16/6/2026 | signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address. | |
| Modificada | Baja (3.6) | 0.38% | — | Mantis | 7/8/2003 | 16/6/2026 | Mantis 0.17.5 y anteriores almacena sus contraseñas de base de datos en un fichero de configuración legible por todo el mundo, lo que permite a usuarios locales realizar operaciones de base de datos no permitidas. | |
| Modificada | Alta (10) | 2.2% | — | Mantis | 4/10/2002 | 16/6/2026 | Multiple SQL injection vulnerabilities in Mantis 0.17.2 and earlier, when running without magic_quotes_gpc enabled, allows remote attackers to gain privileges or perform unauthorized database operations via modified form fields, e.g. to account_update.php. | |
| Modificada | Alta (7.5) | 2.8% | — | Mantis | 4/10/2002 | 16/6/2026 | config_inc2.php in Mantis before 0.17.4 allows remote attackers to execute arbitrary code or read arbitrary files via the parameters (1) g_bottom_include_page, (2) g_top_include_page, (3) g_css_include_file, (4) g_meta_include_file, or (5) a cookie. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Mantis | 4/10/2002 | 16/6/2026 | summary_graph_functions.php in Mantis 0.17.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the g_jpgraph_path parameter to reference the location of the PHP code. | |
| Modificada | Alta (7.5) | 1.4% | — | Mantis | 4/10/2002 | 16/6/2026 | The "View Bugs" page (view_all_bug_page.php) in Mantis 0.17.4a and earlier includes summaries of private bugs for users that do not have access to any projects. | |
| Modificada | Media (5) | 1.4% | — | Mantis | 4/10/2002 | 16/6/2026 | print_all_bug_page.php in Mantis 0.17.3 and earlier does not verify the limit_reporters option, which allows remote attackers to view bug summaries for bugs that would otherwise be restricted. | |
| Modificada | Media (5) | 1.5% | — | Mantis | 4/10/2002 | 16/6/2026 | Mantis before 0.17.4 allows remote attackers to list project bugs without authentication by modifying the cookie that is used by the "View Bugs" page. | |
| Modificada | Media (5) | 1.6% | — | Mantis | 4/10/2002 | 16/6/2026 | Mantis 0.17.4a and earlier allows remote attackers to view private bugs by modifying the f_id bug ID parameter to (1) bug_update_advanced_page.php, (2) bug_update_page.php, (3) view_bug_advanced_page.php, or (4) view_bug_page.php. |