Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3246▲ 704 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

2412 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)3.7%💥 ExploitUpoint @1 File Store19/3/200616/6/2026
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8)…
ModificadaMedia (5.8)1.4%—Upoint AT1 File Store19/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script or HTML via the (1) real_name, (2) email, and (3) login parameters.
ModificadaMedia (4.3)1.9%💥 ExploitJcink.com Textfilebb14/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value.
ModificadaMedia (5)1.8%—Popfile24/2/200616/6/2026
POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages.
ModificadaAlta (10)1.7%—Noofs Team Network Object Oriented File System18/2/200616/6/2026
Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors.
ModificadaAlta (7.2)0.40%—Maynard Johnson Oprofile8/2/200616/6/2026
Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs. NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using…
ModificadaMedia (5)1.7%—Curtis Farnham Files Xaraya Module7/2/200616/6/2026
Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences.
ModificadaMedia (6.4)1.9%—Intervations Filecopa21/1/200616/6/2026
Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands.
ModificadaBaja (2.1)0.40%—Richard Dawe File Extattr4/1/200616/6/2026
Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.
ModificadaMedia (5)1.7%—Efilego31/12/200516/6/2026
upload.exe in eFileGo 3.01 allows remote attackers to cause a denial of service (CPU consumption) via an argument with an invalid directory name.
ModificadaAlta (7.5)4.4%💥 ExploitEfilego31/12/200516/6/2026
Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files via a ... (triple dot) in (1) the URL on port 608 and (2) the argument to upload.exe.
ModificadaAlta (7.5)3.7%—MantisAIMantis BUG File ADDAIMantis BUG ReportAIMantis BUG Report Advanced PageAI+128/12/200516/6/2026
Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_file_add.php, (2) bug_report.php, (3) bug_report_advanced_page.php, and (4) proj_doc_add_page.php.
ModificadaAlta (7.5)1.2%💥 ExploitPHP Arena Pafiledb17/12/200516/6/2026
SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and (2) id parameter.
ModificadaAlta (7.5)1.4%—Tawbaware Filelister6/12/200516/6/2026
SQL injection vulnerability in FileLister 0.51 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameters, possibly the searchwhat parameter to definesearch.jsp.
ModificadaAlta (7.5)5.6%—Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+1530/11/200516/6/2026
Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.
ModificadaAlta (7.8)53%💥 ExploitFilezilla Server Terminal16/11/200516/6/2026
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.
ModificadaMedia (4.3)1.2%💥 ExploitSymantec Veritas Cluster ServerSymantec Veritas Sanpoint Control QuickstartSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System16/11/200516/6/2026
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog,…
ModificadaMedia (5)2.4%—Solarwinds Serv-u File Server2/11/200516/6/2026
Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and…
ModificadaMedia (4.6)0.31%—Ttxn File Transfer Anywhere22/9/200516/6/2026
File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges.
ModificadaMedia (4.6)0.50%💥 ExploitFilezilla14/9/200516/6/2026
NOTE: this issue has been disputed by the vendor. FileZilla 2.2.14b and 2.2.15, and possibly earlier versions, when "Use secure mode" is disabled, uses a weak encryption scheme to store the user's password in the configuration settings file, which allows local users to obtain sensitive information. NOTE: the vendor…
ModificadaAlta (7.5)1.5%—Eric Fichot Downfile7/9/200516/6/2026
DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.
ModificadaMedia (4.3)1.2%—Eric Fichot Downfile7/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php.
ModificadaAlta (7.5)1.3%—PHP Arena Pafiledb30/8/200516/6/2026
SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL commands via the username value in the pafiledbcookie cookie.
ModificadaAlta (10)4.8%—Ares Fileshare3/8/200516/6/2026
Desbordamiento de búfer en Ares FileShare 1.1 permite que atacantes remotos o usuarios locales ejecuten código arbitrario mediante (1) parámetros de configuración largos en el fichero de configuración (ares.conf), o (2) string de búsqueda largo.
ModificadaMedia (5)1.3%—Planetdns Planetfileserver6/7/200516/6/2026
mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.