Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.6% | 💥 Exploit | Invision Power Services Invision BoardInvision Power Services Invision Power Board | 26/4/2006 | 16/6/2026 | SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters. | |
| Modificada | Media (6.8) | 25% | 💥 Exploit | Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team Services | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2)… | |
| Modificada | Media (5) | 1.9% | — | Cisco Content Services Switch 11500 | 5/4/2006 | 16/6/2026 | Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid, but obsolete" or (2) "specially crafted" HTTP requests. | |
| Modificada | Media (5.5) | 0.29% | — | BusyboxAvaya Aura Application Enablement ServicesAvaya Aura SIP Enablement ServicesAvaya Message Networking+1 | 4/4/2006 | 16/6/2026 | BusyBox 1.1.1 no utiliza una "sal" cuando genera contraseñas, lo que facilita a usuarios locales adivinar contraseñas a partir de un fichero de contraseñas robado usando técnicas como tablas "rainbow". | |
| Modificada | Media (6.8) | 1.3% | — | Invision Power Services Invision Power Board | 23/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.1.5 and earlier before 20060308 allows remote attackers to inject arbitrary web script or HTML via a Private Message (PM) in certain circumstances. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Invision Power Services Invision Power Board | 21/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Invision Power Board 2.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) result_type, (2) search_in, (3) nav, (4) forums, and (5) s parameters in the Search action to index.php; (6) st parameter to index.php with showtopics set to 1;… | |
| Modificada | Media (5.8) | 1.1% | — | Invision Power Services Invision Power Board | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer. | |
| Modificada | Alta (7.5) | 1.2% | — | Invision Power Services Invision Power Board | 19/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060105 allow remote attackers to execute arbitrary SQL commands via cookies, related to (1) arrays of id/stamp pairs and (2) the keys in arrays of key/value pairs in ipsclass.php; (3) the topics variable in usercp.php; and… | |
| Modificada | Media (4.3) | 1.3% | — | Virtual Communication Services Vpmi Enterprise | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Service_Requests.asp in VPMi Enterprise 3.3 allows remote attackers to inject arbitrary web script or HTML via the Request_Name_Display parameter. | |
| Modificada | Media (5.1) | 1.2% | — | Invision Power Services Invision Power Board | 19/3/2006 | 16/6/2026 | Invision Power Board 2.1.4 allows remote attackers to hijack sessions and possibly gain administrative privileges by obtaining the session ID from the s parameter, then replaying it in another request. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Invision Power Services Invision Power Board | 9/3/2006 | 16/6/2026 | SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter. | |
| Modificada | Media (5) | 1.3% | — | Invision Power Services Invision Power Board | 28/2/2006 | 16/6/2026 | Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to list directory contents via a direct request to multiple directories, including (1) sources/loginauth/convert/, (2) sources/portal_plugins/, (3) cache/skin_cache/cacheid_2/, (4) ips_kernel/PEAR/, (5) ips_kernel/PEAR/Text/, (6)… | |
| Modificada | Media (5) | 1.4% | — | Invision Power Services Invision Power Board | 28/2/2006 | 16/6/2026 | Invision Power Board (IPB) 2.1.4 and earlier allows remote attackers to view sensitive information via a direct request to multiple PHP scripts that include the full path in error messages, including (1) PEAR/Text/Diff/Renderer/inline.php, (2) PEAR/Text/Diff/Renderer/unified.php, (3) PEAR/Text/Diff3.php, (4)… | |
| Modificada | Alta (7.5) | 1.4% | — | Virtual Communication Services Vpmi Enterprise | 25/2/2006 | 16/6/2026 | SQL injection vulnerability in VCS Virtual Program Management Intranet (VPMi) Enterprise 3.3 allows remote attackers to execute arbitrary SQL commands via the UpdateID0 parameter to Service_Requests.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.… | |
| Modificada | Baja (2.6) | 8.5% | 💥 Exploit | Invision Power Services Invision Power Board | 25/2/2006 | 16/6/2026 | index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users. | |
| Modificada | Media (5) | 2.4% | — | Cisco Application AND Content Networking SoftwareCisco ATACisco Subscriber Edge Services ManagerCisco IP Phone 7902+3 | 31/12/2005 | 16/6/2026 | Cisco IP Phones 7902/7905/7912, ATA 186/188, Unity Express, ACNS, and Subscriber Edge Services Manager (SESM) allows remote attackers to cause a denial of service (crash or instability) via a compressed DNS packet with a label length byte with an incorrect offset. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Alta (7.8) | 87% | 💥 Exploit | Microsoft Internet Information Services | 20/12/2005 | 16/6/2026 | The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as… | |
| Modificada | Alta (7.8) | 2.8% | — | SUN Wbem Services | 20/12/2005 | 16/6/2026 | Unspecified vulnerability in WBEM Services A.01.x before A.01.05.12 and A.02.x before A.02.00.08 on HP-UX B.11.00 through B.11.23 allows remote attackers to cause an unspecified denial of service via unknown attack vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | SUN Java Communications Services Delegated Administrator | 7/12/2005 | 16/6/2026 | Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif. | |
| Modificada | Media (5) | 5.2% | — | Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+4 | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details… | |
| Modificada | Media (4) | 1.3% | — | Invision Power Services Invision Board | 16/11/2005 | 16/6/2026 | Vulnerabilidad de atravesammiento de directorios en Administrador de Tareas de Invision Power Board 2.0.1 (IP.Board) permite a atacantes remotos limitados incluir ficheros mediante un .. (punto punto) en el campo Task PHP File To Run. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Invision Power Services Invision Board | 16/11/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Invision Power Board 2.1 permite a atacantes remotos inyectar web scritp o HTML de su elección mediante los parámetros (1) adsess, (2) name y (3) description en admin.php, y (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address, (8)… | |
| Modificada | Media (6.5) | 1.9% | — | Invision Power Services Invision Board | 16/11/2005 | 16/6/2026 | Vulnerabilidad de inyección directa de código en Administrador de Tareas de Invision Power Board 2.0.1 permite a atacantes remotos limitados ejecutar código de su elección referenciando el fichero en el campo Task PHP File To Run y seleccionando Run Task Now. | |
| Modificada | Media (4.3) | 1.2% | — | Invision Power Services Invision Gallery | 3/11/2005 | 16/6/2026 | Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued… |