Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

2412 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.8%—PHP Arena Pafiledb15/6/200516/6/2026
Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.
ModificadaAlta (7.5)2.4%💥 ExploitPHP Arena Pafiledb15/6/200516/6/2026
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.
ModificadaMedia (4.3)1.3%—PHP Arena Pafiledb15/6/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php).
ModificadaMedia (5)1.4%—File Upload Manager12/6/200516/6/2026
File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.
ModificadaAlta (7.5)1.6%—Adam Mmedici File Upload Manager12/6/200516/6/2026
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.
ModificadaAlta (7.5)1.7%—Fastream Netfile FTP WEB Server18/5/200516/6/2026
The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.
ModificadaMedia (5)3.1%💥 ExploitNiteenterprises Remote File Manager16/5/200516/6/2026
NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.
ModificadaAlta (7.5)1.7%—Net56 File Manager16/5/200516/6/2026
SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.
ModificadaMedia (4.6)0.76%💥 ExploitExoticsoft FilepocketAI3/5/200516/6/2026
ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.
ModificadaMedia (5)2.2%💥 ExploitFilezilla-project Filezilla Server2/5/200516/6/2026
FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.
ModificadaMedia (5)5.9%💥 ExploitPHP Arena Pafiledb2/5/200516/6/2026
Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)2.4%💥 ExploitPHP Arena Pafiledb2/5/200516/6/2026
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.
ModificadaMedia (4.3)3.6%💥 ExploitPHP Arena Pafiledb2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.
ModificadaMedia (5)1.2%—PHP Arena Pafiledb2/5/200516/6/2026
pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script.
ModificadaMedia (5)2.2%💥 ExploitFilezilla-project Filezilla Server2/5/200516/6/2026
FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.
ModificadaMedia (5)1.2%—PHP Arena Pafiledb2/5/200516/6/2026
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or…
ModificadaAlta (7.5)1.9%—PHP Arena Pafiledb2/5/200516/6/2026
pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php.
ModificadaMedia (4.3)2.2%💥 ExploitPHP Labs Profile20/4/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.
ModificadaMedia (4.6)0.36%—Rsnapshot Filesystem Snapshot Utility10/4/200516/6/2026
The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.
ModificadaMedia (5)5.1%💥 ExploitPHP Arena Pafiledb12/3/200516/6/2026
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message.
ModificadaMedia (4.3)0.95%—PHP Arena Pafiledb8/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using pafiledb.php.
ModificadaAlta (7.5)15%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+199/2/200516/6/2026
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
ModificadaBaja (2.1)0.39%—Netatalk Open Source Apple File Share Protocol SuiteMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core9/2/200516/6/2026
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
ModificadaAlta (7.5)21%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+1927/1/200516/6/2026
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file…
ModificadaAlta (7.5)15%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+1927/1/200516/6/2026
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.