Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 702 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Powerportal | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web script or HTML via the (1) SUBJECT or (2) MESSAGE field. | |
| Modificada | Media (4.3) | 4.6% | 💥 Exploit | Codeworx Technologies Dcp-portal | 31/12/2004 | 16/6/2026 | CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter. | |
| Modificada | Media (4.3) | 5.3% | 💥 Exploit | Codeworx Technologies Dcp-portal | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid parameter in annoucement.php; (7) the cid… | |
| Modificada | Media (4.3) | 1.3% | — | Silent-storm Portal | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter. | |
| Modificada | Alta (7.5) | 6.8% | 💥 Exploit | Silent-storm PortalAI | 31/12/2004 | 16/6/2026 | profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator. | |
| Modificada | Media (5) | 1.5% | — | Hitachi Cosminexus Portal FrameworkAI | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Mambo Portal | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the com_remository option. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | 2wire Homeportal | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Ocportal | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script. | |
| Modificada | Media (5) | 59% | 💥 Exploit | Nortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+15 | 23/12/2004 | 16/6/2026 | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number… | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Aprox PHP PortalAI | 23/11/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en index.php de Aprox PHP Portal permite a atacantes remotos la lectura de ficheros arbitrarios mediante su ruta completa en el parámetro show. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Maxwebportal | 23/11/2004 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en MaxWebPortal permite a atacantes remotos ejecutar script de su elección como otros usuarios mediante (1) el parámetro sub_name de dl_showall.asp, (2) el parámetro SentTo en Mensajes Personales, (3) el HTTP_REFERER de down.asp, o (4) en… | |
| Modificada | Alta (7.5) | 1.3% | — | Maxwebportal | 23/11/2004 | 16/6/2026 | Vulnerabilidad de inyección de SQL en MaxWebPortal permite a atacantes remotos inyectar código SQL arbitrario de su elección y obtener información sensible mediante el parámetro SendTo en Mensajes Personales. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Coolphp WEB Portal | 16/10/2004 | 16/6/2026 | Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Coolphpweb Portal | 16/10/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | CA Unicenter Management PortalAI | 21/9/2004 | 16/6/2026 | The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames. | |
| Modificada | Media (5) | 34% | — | Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+14 | 18/8/2004 | 16/6/2026 | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by… | |
| Modificada | Media (5) | 1.5% | — | Powerportal | 6/8/2004 | 16/6/2026 | PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message. | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Powerportal | 6/8/2004 | 16/6/2026 | Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter. | |
| Modificada | Media (6.8) | 2.0% | — | Powerportal | 6/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script or HTML via the (1) id parameter to the (a) private_messages module; (2) search parameter to the (b) links and (c) content modules; and (3) files parameter to the gallery module. | |
| Modificada | Alta (7.2) | 2.6% | 💥 Exploit | Oracle Application ServerOracle Application Server PortalOracle Database Server LiteOracle8i+1 | 30/7/2004 | 16/6/2026 | The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Jportal WEB Portal | 28/5/2004 | 16/6/2026 | SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Liferay Enterprise Portal | 22/5/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject. | |
| Modificada | Media (6.8) | 8.1% | — | Microsoft Sharepoint Portal Server | 4/5/2004 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Microsoft SharePoint Portal Server 2001 permite a atacantes remotos procesar contenido web elegido arbitrariamente y robar galletitas (cookies) mediante ciertos scripts de servidor. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Iatek Portalapp | 4/1/2004 | 16/6/2026 | PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb. |