Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2295 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)9.8%💥 ExploitCisco Adaptive Security Appliance SoftwareCisco PIX FirewallCisco Firewall Services ModuleCisco PIX Firewall Software9/5/200616/6/2026
Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the…
ModificadaMedia (5)3.4%💥 ExploitBugada Andrea PHP Advanced Transfer Manager14/3/200616/6/2026
PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.
ModificadaAlta (7.8)2.2%—TEG Tenes Empanadas Graciela10/3/200616/6/2026
Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (application crash) by creating multiple users with long, identical nicknames, which triggers an off-by-one error.
ModificadaAlta (7.1)1.6%—ATI Catalyst DriverIntel Display Adapter Driver31/12/200516/6/2026
Drivers for certain display adapters, including (1) an unspecified ATI driver and (2) an unspecified Intel driver, might allow remote attackers to cause a denial of service (system crash) via a large JPEG image, as demonstrated in Internet Explorer using stoopid.jpg with a width and height of 9999999.
ModificadaAlta (7.5)2.6%—Cisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+1722/12/200516/6/2026
The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the…
ModificadaMedia (4.3)1.2%—Liquid Bytes Technologies Adaptive Website Framework20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in account.html in Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModificadaMedia (5)1.4%—Liquid Bytes Technologies Adaptive Website FrameworkAI20/12/200516/6/2026
Adaptive Website Framework (AWF) 2.10 and earlier allows remote attackers to obtain the full path of the application via an invalid mode parameter to community.html, which leaks the path in an error message.
ModificadaAlta (7.5)2.7%💥 ExploitAdaptive Technology Resource Centre Atutor11/12/200516/6/2026
registration.PHP en ATutor 1.4.1 p12 permite a atacantes remotos ejecutar comandos SQL de su elección mediante una dirección de correo electrónico que termina en un carácter NULL, lo que evita la comprobación mediante expresión regular de PHP. NOTA: es posible que esto sea en realidad un fallo en el código de PHP, en…
ModificadaMedia (5.4)2.6%—Cisco Adaptive Security Appliance Software24/11/200516/6/2026
Condición de carrera en Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), Y 7.0(4), cuando corre una configuración Activo/En Espera y cuando la interfaz LAN de reserva falla, permite a atacantes remotos causar una denegación de servicio (fallo de cortafuegos en espera) enviando respuestas ARP suplantadas de la…
ModificadaMedia (5)5.2%—Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+418/11/200516/6/2026
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details…
ModificadaMedia (4.3)1.9%—Adaptive Technology Resource Centre Atutor1/11/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the _base_href parameter in translate.php, (2) the _base_path parameter in news.inc.php, and (3) the p parameter in add_note.php.
ModificadaAlta (7.5)10%💥 ExploitAdaptive Technology Resource Centre Atutor1/11/200516/6/2026
Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php.
ModificadaMedia (4.3)0.99%—Bugada Andrea PHP Advanced Transfer Manager20/9/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in viewers/txt.php in PHP Advanced Transfer Manager 1.30 allow remote attackers to inject arbitrary web script or HTML via the (1) font, (2) normalfontcolor, or (3) mess[31] parameters.
ModificadaMedia (5)1.2%—Bugada Andrea PHP Advanced Transfer Manager20/9/200516/6/2026
PHP Advanced Transfer Manager 1.30 allows remote attackers to obtain sensitive PHP configuration information via a direct request to test.php.
ModificadaAlta (7.5)1.4%—Bugada Andrea PHP Advanced Transfer Manager20/9/200516/6/2026
PHP Advanced Transfer Manager 1.30 has a default password for the administrator user, which allows remote attackers to upload and execute arbitrary PHP files.
ModificadaMedia (5)1.5%—Bugada Andrea PHP Advanced Transfer Manager20/9/200516/6/2026
Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the current_dir parameter to (2) htm.php or (3) html.php.
ModificadaMedia (4.6)0.78%—Adaptive Technology Resource Centre Atutor16/9/200516/6/2026
config.inc.php in ATutor 1.5.1, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which allows authenticated administrators or educators to execute arbitrary code by uploading files with other executable extensions such as .inc, .php4, or others.
ModificadaAlta (7.5)1.7%💥 ExploitAdaptive Technology Resource Centre Atutor16/9/200516/6/2026
SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field.
ModificadaMedia (5)2.9%💥 ExploitAdaptive Technology Resource Centre Atutor16/9/200516/6/2026
ATutor 1.5.1, and possibly earlier versions, stores temporary chat logs under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain user chat conversations via direct requests to those files.
ModificadaMedia (4.3)3.6%💥 ExploitAdaptive Technology Resource Centre Atutor23/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) course parameter in login.php or (2) words parameter in search.php.
ModificadaMedia (4.3)1.2%—Dada Mail17/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in Dada Mail before 2.10 Alpha 1 allows remote attackers to execute arbitrary Javascript via archived messages.
ModificadaMedia (4.3)2.9%💥 ExploitAdaptive Technology Resource Centre Atutor16/6/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.3 and 1.5 RC 1 allow remote attackers to inject arbitrary web script or HTML via the (1) show_course parameter to browse.php, (2) subject parameter to contact.php, (3) cid parameter to content.php, (4) l parameter to inbox/send_message.php, the (5)…
ModificadaAlta (7.5)1.6%—Adam Mmedici File Upload Manager12/6/200516/6/2026
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.
ModificadaAlta (7.5)6.6%💥 ExploitBugada Andrea PHP Advanced Transfer Manager20/5/200516/6/2026
PHP remote file inclusion vulnerability in common.php in phpATM 1.21, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the include_location parameter to index.php.
ModificadaAlta (7.5)5.1%💥 ExploitBugada Andrea PHP Advanced Transfer Manager16/5/200516/6/2026
PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.