Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | PHP Arena Pafiledb | 17/7/2007 | 16/6/2026 | SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to index.php, a different vector than CVE-2005-2000. | |
| Modificada | Alta (10) | 4.8% | — | Karl Dahlke Edbrowse | 31/12/2006 | 16/6/2026 | Stack-based buffer overflow in http.c in Karl Dahlke Edbrowse (aka Command line editor browser) 3.1.3 allows remote attackers to execute arbitrary code by operating an FTP server that sends directory listings with (1) long user names or (2) long group names. | |
| Modificada | Alta (7.5) | 1.2% | — | Redbinaria Siap CMS | 4/12/2006 | 16/6/2026 | SQL injection vulnerability in login.asp in Redbinaria Sistema Integrado de Administracion de Portales (SIAP) allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Baja (2.1) | 0.41% | — | DragonflybsdFreebsdMidnightbsdNetbsd+1 | 21/11/2006 | 16/6/2026 | Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Speedberg | 24/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SpeedBerg 1.2beta1 allow remote attackers to execute arbitrary PHP code via a URL in the SPEEDBERG_PATH parameter to (1) entrancePage.tpl.php, (2) generalToolBox.tlb.php, (3) myToolBox.tlb.php, (4) scriplet.inc.php, (5) simplePage.tpl.php, (6) speedberg.class.php,… | |
| Modificada | Crítica (9.8) | 3.1% | 💥 Exploit | Redblog | 27/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Redblog | 26/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Mxbb PortalPHP Arena Pafiledb | 15/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Redblog | 10/3/2006 | 16/6/2026 | SQL injection vulnerability in rss.php in RedBLoG 0.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. | |
| Modificada | Baja (2.6) | 0.92% | — | Ncipher Dse200 Document Sealing EngineNcipher NcoreNcipher NforceNcipher Securedb+4 | 9/3/2006 | 16/6/2026 | nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | PHP Arena Pafiledb | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and (2) id parameter. | |
| Modificada | Media (5) | 1.1% | — | Thesitewizard.com Chfeedback.pl Feedback Form Perl Script | 8/9/2005 | 16/6/2026 | CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers. | |
| Modificada | Alta (7.5) | 1.3% | — | PHP Arena Pafiledb | 30/8/2005 | 16/6/2026 | SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL commands via the username value in the pafiledbcookie cookie. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | PHP Arena Pafiledb | 15/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php. | |
| Modificada | Media (5) | 1.8% | — | PHP Arena Pafiledb | 15/6/2005 | 16/6/2026 | Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter. | |
| Modificada | Media (4.3) | 1.3% | — | PHP Arena Pafiledb | 15/6/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php). | |
| Modificada | Media (5) | 1.2% | — | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or… | |
| Modificada | Alta (7.5) | 1.9% | — | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php. | |
| Modificada | Media (5) | 1.2% | — | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (5) | 5.1% | 💥 Exploit | PHP Arena Pafiledb | 12/3/2005 | 16/6/2026 | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message. | |
| Modificada | Media (4.3) | 0.95% | — | PHP Arena Pafiledb | 8/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using pafiledb.php. | |
| Modificada | Media (5) | 2.3% | — | PHP Arena Pafiledb | 10/1/2005 | 16/6/2026 | paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session. |