Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 704 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2412 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 3.7% | 💥 Exploit | Upoint @1 File Store | 19/3/2006 | 16/6/2026 | SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8)… | |
| Modificada | Media (5.8) | 1.4% | — | Upoint AT1 File Store | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signup.php in @1 File Store 2006.03.07 allows remote attackers to inject arbitrary web script or HTML via the (1) real_name, (2) email, and (3) login parameters. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Jcink.com Textfilebb | 14/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value. | |
| Modificada | Media (5) | 1.8% | — | Popfile | 24/2/2006 | 16/6/2026 | POPFile before 0.22.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors involving character sets within e-mail messages. | |
| Modificada | Alta (10) | 1.7% | — | Noofs Team Network Object Oriented File System | 18/2/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in the (1) Filesystem in USErspace (FUSE) client and (2) NOOFS daemon in in Network Object Oriented File System (NOOFS) before 0.9.0 have unspecified impact and attack vectors. | |
| Modificada | Alta (7.2) | 0.40% | — | Maynard Johnson Oprofile | 8/2/2006 | 16/6/2026 | Untrusted search path vulnerability in opcontrol in OProfile 0.9.1 and earlier allows local users to execute arbitrary commands via a modified PATH that references malicious (1) which or (2) dirname programs. NOTE: while opcontrol normally is not run setuid, a common configuration suggests accessing opcontrol using… | |
| Modificada | Media (5) | 1.7% | — | Curtis Farnham Files Xaraya Module | 7/2/2006 | 16/6/2026 | Directory traversal vulnerability in Files Xaraya module before 0.5.1, when the Archive Directory field on the Modify Config page is blank, allows remote attackers to access files outside of the web root via ".." (dot dot) sequences. | |
| Modificada | Media (6.4) | 1.9% | — | Intervations Filecopa | 21/1/2006 | 16/6/2026 | Directory traversal vulnerability in Intervations FileCOPA FTP Server 1.01 allows remote attackers to read and write arbitrary files via a .. (dot dot) in the (1) STOR and (2) RETR commands. | |
| Modificada | Baja (2.1) | 0.40% | — | Richard Dawe File Extattr | 4/1/2006 | 16/6/2026 | Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors. | |
| Modificada | Media (5) | 1.7% | — | Efilego | 31/12/2005 | 16/6/2026 | upload.exe in eFileGo 3.01 allows remote attackers to cause a denial of service (CPU consumption) via an argument with an invalid directory name. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Efilego | 31/12/2005 | 16/6/2026 | Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files via a ... (triple dot) in (1) the URL on port 608 and (2) the argument to upload.exe. | |
| Modificada | Alta (7.5) | 3.7% | — | MantisAIMantis BUG File ADDAIMantis BUG ReportAIMantis BUG Report Advanced PageAI+1 | 28/12/2005 | 16/6/2026 | Mantis before 0.19.4 allows remote attackers to bypass the file upload size restriction by modifying the max_file_size parameter to (1) bug_file_add.php, (2) bug_report.php, (3) bug_report_advanced_page.php, and (4) proj_doc_add_page.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | PHP Arena Pafiledb | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and (2) id parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Tawbaware Filelister | 6/12/2005 | 16/6/2026 | SQL injection vulnerability in FileLister 0.51 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameters, possibly the searchwhat parameter to definesearch.jsp. | |
| Modificada | Alta (7.5) | 5.6% | — | Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+15 | 30/11/2005 | 16/6/2026 | Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive. | |
| Modificada | Alta (7.8) | 53% | 💥 Exploit | Filezilla Server Terminal | 16/11/2005 | 16/6/2026 | Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Symantec Veritas Cluster ServerSymantec Veritas Sanpoint Control QuickstartSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System | 16/11/2005 | 16/6/2026 | Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog,… | |
| Modificada | Media (5) | 2.4% | — | Solarwinds Serv-u File Server | 2/11/2005 | 16/6/2026 | Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE: it is not clear whether items (2) and… | |
| Modificada | Media (4.6) | 0.31% | — | Ttxn File Transfer Anywhere | 22/9/2005 | 16/6/2026 | File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges. | |
| Modificada | Media (4.6) | 0.50% | 💥 Exploit | Filezilla | 14/9/2005 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. FileZilla 2.2.14b and 2.2.15, and possibly earlier versions, when "Use secure mode" is disabled, uses a weak encryption scheme to store the user's password in the configuration settings file, which allows local users to obtain sensitive information. NOTE: the vendor… | |
| Modificada | Alta (7.5) | 1.5% | — | Eric Fichot Downfile | 7/9/2005 | 16/6/2026 | DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php. | |
| Modificada | Media (4.3) | 1.2% | — | Eric Fichot Downfile | 7/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_form.php. | |
| Modificada | Alta (7.5) | 1.3% | — | PHP Arena Pafiledb | 30/8/2005 | 16/6/2026 | SQL injection vulnerability in auth.php in PaFileDB 3.1, when authmethod is set to cookies, allows remote attackers to execute arbitrary SQL commands via the username value in the pafiledbcookie cookie. | |
| Modificada | Alta (10) | 4.8% | — | Ares Fileshare | 3/8/2005 | 16/6/2026 | Desbordamiento de búfer en Ares FileShare 1.1 permite que atacantes remotos o usuarios locales ejecuten código arbitrario mediante (1) parámetros de configuración largos en el fichero de configuración (ares.conf), o (2) string de búsqueda largo. | |
| Modificada | Media (5) | 1.3% | — | Planetdns Planetfileserver | 6/7/2005 | 16/6/2026 | mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request. |