Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 685 respecto a la semana anterior
Críticas / altas1521▲ 128 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2295 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.0% | — | Sybase Adaptive Server Enterprise | 2/5/2005 | 16/6/2026 | The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port. | |
| Modificada | Media (4.3) | 0.94% | — | Adalis D-forum | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.php3. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | ADA Imgsvr | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and earlier is also affected. | |
| Modificada | Alta (7.5) | 4.2% | — | ADA Imgsvr | 31/12/2004 | 16/6/2026 | Buffer overflow in ADA Image Server (ImgSvr) 0.4 allows remote attackers to cause a denial of service (web server crash) or execute arbitrary code via a long GET request. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | ADA Imgsvr | 31/12/2004 | 16/6/2026 | Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a trailing %00 (null). | |
| Modificada | Alta (10) | 8.5% | — | Sybase Adaptive Server Enterprise | 22/12/2004 | 16/6/2026 | Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database… | |
| Modificada | Alta (7.5) | 5.0% | — | Webdav CadaverWebdav NeonDebian Linux | 7/7/2004 | 16/6/2026 | Desbordamiento de búfer en la función de proceso de de fecha ne_rfc1036_parse de la librería neon (libneon) 0.24.5 y anteriores, usada en cadaver 0.22 permite a servidores WebDAV ejecutar código arbitrario en el cliente. | |
| Modificada | Media (4.6) | 1.7% | 💥 Exploit | Adam Webb Nukejokes | 8/5/2004 | 16/6/2026 | SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Adam Webb Nukejokes | 8/5/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to inject arbitrary HTML or web script via the (1) cat parameter in a CatView function or (2) jokeid parameter in a JokeView function. | |
| Modificada | Media (5) | 1.4% | — | Adam Webb NukejokesAI | 8/5/2004 | 16/6/2026 | NukeJokes 1.7 and 2 Beta allows remote attackers to obtain the full path of the server via (1) a direct call to mainfunctions.php, (2) an invalid jokeid parameter in a JokeView function or (3) an invalid cat parameter in a CatView function, which reveals the path in a PHP error message. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Adalis Infomatique D Forum | 31/12/2003 | 16/6/2026 | PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP code via a URL in the (1) my_header parameter to header.php3 or (2) my_footer parameter to footer.php3. | |
| Modificada | Media (4.3) | 1.3% | — | Myabracadaweb | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in header.php in MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the ma_kw parameter. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | Myabracadaweb | 31/12/2003 | 16/6/2026 | MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other parameter, which reveals the installation path in an error message. | |
| Modificada | Media (5) | 1.8% | — | Sybase Adaptive Server Enterprise | 15/12/2003 | 16/6/2026 | Sybase Adaptive Serve Enterprise (ASE) 12.5 permite a atacantes remotos causar una denegación de servicio (cuelgue) mediante una contraseña remota con una longitud inválida, lo que dispara un desbordamiento de búfer en el montón. | |
| Modificada | Alta (7.5) | 1.1% | — | Adam Megacz Tinyssl | 11/4/2003 | 16/6/2026 | TinySSL 1.02 y anteriores no verifica las Resticciones Básicas de un certificado firmado por una AC (Autoridad Certificadora) intermedia, lo que permite a atacantes remotos suplantar los certificados de sitios de confianza mediante un ataque de 'hombre en el medio'. | |
| Modificada | Alta (10) | 7.7% | — | Sybase Adaptive Server | 31/12/2002 | 16/6/2026 | Multiple buffer overflows in Sybase Adaptive Server 12.0 and 12.5 allow remote attackers to execute arbitrary code via (1) a long parameter to the xp_freedll extended stored procedure or (2) a long database name argument to the DBCC CHECKVERIFY function. | |
| Modificada | Baja (1.2) | 0.26% | — | ADA Core Technologies Gnat PRO Native | 29/5/2002 | 16/6/2026 | Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files. | |
| Modificada | Media (5) | 1.7% | — | Sybase Adaptive Server Anywhere | 2/8/2001 | 16/6/2026 | Sybase Adaptive Server Anywhere Database Engine 6.0.3.2747 and earlier as included with Symantec Ghost 6.5 allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to port 2638. | |
| Modificada | Alta (10) | 4.0% | — | Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+11 | 12/3/2001 | 16/6/2026 | Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Armada Design Master Index | 19/12/2000 | 23/9/2026 | Vulnerabilidad de salto de directorio en el script CGI search.cgi de Armada Master Index permite a atacantes remotos leer archivos arbitrarios mediante un ataque de '..' (punto punto) en el parámetro 'catigory'. |