Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3246▲ 685 respecto a la semana anterior
Críticas / altas1521▲ 128 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

2295 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.0%—Sybase Adaptive Server Enterprise2/5/200516/6/2026
The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.
ModificadaMedia (4.3)0.94%—Adalis D-forum2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3.
ModificadaMedia (5)3.5%💥 ExploitADA Imgsvr31/12/200416/6/2026
Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected.
ModificadaAlta (7.5)4.2%—ADA Imgsvr31/12/200416/6/2026
Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request.
ModificadaMedia (5)3.8%💥 ExploitADA Imgsvr31/12/200416/6/2026
Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null).
ModificadaAlta (10)8.5%—Sybase Adaptive Server Enterprise22/12/200416/6/2026
Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database…
ModificadaAlta (7.5)5.0%—Webdav CadaverWebdav NeonDebian Linux7/7/200416/6/2026
Desbordamiento de búfer en la función de proceso de de fecha ne_rfc1036_parse de la librería neon (libneon) 0.24.5 y anteriores, usada en cadaver 0.22 permite a servidores WebDAV ejecutar código arbitrario en el cliente.
ModificadaMedia (4.6)1.7%💥 ExploitAdam Webb Nukejokes8/5/200416/6/2026
SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.
ModificadaMedia (4.3)1.8%💥 ExploitAdam Webb Nukejokes8/5/200416/6/2026
Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function.
ModificadaMedia (5)1.4%—Adam Webb NukejokesAI8/5/200416/6/2026
NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message.
ModificadaAlta (7.5)2.5%💥 ExploitAdalis Infomatique D Forum31/12/200316/6/2026
PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3.
ModificadaMedia (4.3)1.3%—Myabracadaweb31/12/200316/6/2026
Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter.
ModificadaMedia (5)7.0%💥 ExploitMyabracadaweb31/12/200316/6/2026
MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message.
ModificadaMedia (5)1.8%—Sybase Adaptive Server Enterprise15/12/200316/6/2026
Sybase Adaptive Serve Enterprise (ASE) 12.5 permite a atacantes remotos causar una denegación de servicio (cuelgue) mediante una contraseña remota con una longitud inválida, lo que dispara un desbordamiento de búfer en el montón.
ModificadaAlta (7.5)1.1%—Adam Megacz Tinyssl11/4/200316/6/2026
TinySSL 1.02 y anteriores no verifica las Resticciones Básicas de un certificado firmado por una AC (Autoridad Certificadora) intermedia, lo que permite a atacantes remotos suplantar los certificados de sitios de confianza mediante un ataque de 'hombre en el medio'.
ModificadaAlta (10)7.7%—Sybase Adaptive Server31/12/200216/6/2026
Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter to the xp_freedll extended stored procedure or (2) a long database name argument to the DBCC CHECKVERIFY function.
ModificadaBaja (1.2)0.26%—ADA Core Technologies Gnat PRO Native29/5/200216/6/2026
Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.
ModificadaMedia (5)1.7%—Sybase Adaptive Server Anywhere2/8/200116/6/2026
Sybase Adaptive Server Anywhere Database Engine 6.0.3.2747 and earlier as included with Symantec Ghost 6.5 allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to port 2638.
ModificadaAlta (10)4.0%—Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+1112/3/200116/6/2026
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
ModificadaMedia (5)7.9%💥 ExploitArmada Design Master Index19/12/200023/9/2026
Vulnerabilidad de salto de directorio en el script CGI search.cgi de Armada Master Index permite a atacantes remotos leer archivos arbitrarios mediante un ataque de '..' (punto punto) en el parámetro 'catigory'.