Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2412 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.8% | — | PHP Arena Pafiledb | 15/6/2005 | 16/6/2026 | Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | PHP Arena Pafiledb | 15/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php. | |
| Modificada | Media (4.3) | 1.3% | — | PHP Arena Pafiledb | 15/6/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter in the viewall action (viewall.php). | |
| Modificada | Media (5) | 1.4% | — | File Upload Manager | 12/6/2005 | 16/6/2026 | File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks. | |
| Modificada | Alta (7.5) | 1.6% | — | Adam Mmedici File Upload Manager | 12/6/2005 | 16/6/2026 | mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action. | |
| Modificada | Alta (7.5) | 1.7% | — | Fastream Netfile FTP WEB Server | 18/5/2005 | 16/6/2026 | The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Niteenterprises Remote File Manager | 16/5/2005 | 16/6/2026 | NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080. | |
| Modificada | Alta (7.5) | 1.7% | — | Net56 File Manager | 16/5/2005 | 16/6/2026 | SQL injection vulnerability in login.asp for Net56 Browser Based File Manager 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field. | |
| Modificada | Media (4.6) | 0.76% | 💥 Exploit | Exoticsoft FilepocketAI | 3/5/2005 | 16/6/2026 | ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Filezilla-project Filezilla Server | 2/5/2005 | 16/6/2026 | FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | Cross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php. | |
| Modificada | Media (5) | 1.2% | — | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Filezilla-project Filezilla Server | 2/5/2005 | 16/6/2026 | FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings. | |
| Modificada | Media (5) | 1.2% | — | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or… | |
| Modificada | Alta (7.5) | 1.9% | — | PHP Arena Pafiledb | 2/5/2005 | 16/6/2026 | pafiledb.php in Pafiledb 3.1 may allow remote attackers to execute arbitrary PHP code via a modified action parameter that is used in an include statement for login.php. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | PHP Labs Profile | 20/4/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters. | |
| Modificada | Media (4.6) | 0.36% | — | Rsnapshot Filesystem Snapshot Utility | 10/4/2005 | 16/6/2026 | The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files. | |
| Modificada | Media (5) | 5.1% | 💥 Exploit | PHP Arena Pafiledb | 12/3/2005 | 16/6/2026 | paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a PHP error message. | |
| Modificada | Media (4.3) | 0.95% | — | PHP Arena Pafiledb | 8/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using pafiledb.php. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 9/2/2005 | 16/6/2026 | Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Baja (2.1) | 0.39% | — | Netatalk Open Source Apple File Share Protocol SuiteMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core | 9/2/2005 | 16/6/2026 | The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. |