Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3135▲ 554 respecto a la semana anterior
Críticas / altas1494▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Hinton Design Phphd | 8/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in add.php in Hinton Design phphd 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (6.4) | 2.3% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter. | |
| Modificada | Baja (1.2) | 0.39% | — | Solar Designer Crypt Blowfish | 8/2/2006 | 16/6/2026 | Las funciones crypt_gensalt de huellas digitales ('hashes') de contraseñas basadas en DES extendidas con estilo BSDI y basadas en MD5 con estilo FreeBSD en crypt_blowfish 0.4.7 y anteriores no distribuyen las sales equitativamente y aleatoriamente en el espacio de huellas digitales, lo que hace más fácil a atacantes… | |
| Modificada | Media (4.3) | 1.3% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface. | |
| Modificada | Alta (7.5) | 1.4% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in the administrative interface. | |
| Modificada | Alta (7.5) | 1.7% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication. | |
| Modificada | Media (4.6) | 1.3% | — | Adobe AcrobatAdobe Acrobat ReaderAdobe Creative SuiteAdobe Illustrator+5 | 2/2/2006 | 16/6/2026 | Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs. | |
| Modificada | Alta (7.5) | 1.2% | — | Ideosoft Design Ideocontent Manager | 27/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in IdeoContent Manager allow remote attackers to execute arbitrary SQL commands via the (1) goto_id or (2) mid parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Ideosoft Design Ideocontent Manager | 27/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Epic Designs Eggblog | 21/1/2006 | 16/6/2026 | SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Epic Designs Eggblog | 21/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ades Design Adesguestbook | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter. | |
| Modificada | Media (4.6) | 0.59% | — | Autodesk 3DS MAXAutodesk Architectural DesktopAutodesk AutocadAutodesk Autocad Civil 3D+14 | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329. | |
| Modificada | Alta (7.8) | 1.6% | — | Epic Designs Eggblog | 28/12/2005 | 16/6/2026 | search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability. | |
| Modificada | Media (4.3) | 1.2% | — | Epic Designs Eggblog | 28/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Abledesign D-man | 21/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | Abledesign | 21/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AbleDesign ReSearch 2.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.4% | — | Sensation Designs Kbase Express | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to category.php and (2) search parameters to search.php. | |
| Modificada | Media (4.3) | 0.95% | — | CJ Design CJ TAG Board | 14/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or (6) msg parameter. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (5) | 1.0% | — | Verisign Payflow Link | 10/1/2005 | 16/6/2026 | Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Pensacola WEB Designs Xtremeasp Photogallery | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. |