Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.9% | — | PhpsysinfoAI | 28/8/2026 | 9/9/2026 | phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can supply an allowed address in one of these… | |
| Modificada | Media (6.5) | 0.52% | — | Phpsysinfo | 19/12/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted page in the XML.php file. | |
| Modificada | Alta (8.8) | 0.67% | — | Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+4 | 3/6/2019 | 17/6/2026 | Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes. | |
| Modificada | Alta (8.8) | 0.67% | — | Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+4 | 3/6/2019 | 17/6/2026 | Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes. | |
| Modificada | Media (5.5) | 0.53% | — | Magnicomp Sysinfo | 21/5/2018 | 17/6/2026 | MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file permissions. Confidential information such as password… | |
| Modificada | Alta (7.8) | 0.32% | — | Magnicomp Sysinfo | 30/4/2018 | 17/6/2026 | An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any local user on a Linux/UNIX system to run SysInfo and obtain a root shell, which can be used to compromise the local system. | |
| Modificada | Media (6.7) | 5.3% | — | Magnicomp Sysinfo | 14/3/2017 | 17/6/2026 | A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be… | |
| Modificada | Media (4.3) | 1.3% | — | Phpsysinfo | 30/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Alta (10) | 3.6% | — | Prosysinfo Tftp Server Tftpdwin | 13/5/2007 | 16/6/2026 | Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors. | |
| Modificada | Alta (7.3) | 67% | — | Prosysinfo Tftp Server Tftpdwin | 10/3/2007 | 16/6/2026 | tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948. | |
| Modificada | Alta (7.5) | 55% | — | Prosysinfo Tftp Server Tftpdwin | 23/9/2006 | 16/6/2026 | Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5) | 5.6% | — | Phpsysinfo | 6/7/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists. | |
| Modificada | Alta (7.5) | 8.3% | — | Coder-world Sysinfo | 19/4/2006 | 16/6/2026 | Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php. | |
| Modificada | Media (5) | 6.6% | — | Coder-world Sysinfo | 19/4/2006 | 16/6/2026 | sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action. | |
| Modificada | Media (4.3) | 2.0% | — | Phpsysinfo | 18/11/2005 | 16/6/2026 | HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter. | |
| Modificada | Media (4.3) | 3.7% | — | Phpsysinfo | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php. | |
| Modificada | Media (5) | 5.2% | — | Phpsysinfo | 2/5/2005 | 16/6/2026 | phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message. | |
| Modificada | Baja (3.6) | 1.5% | — | Phpsysinfo | 18/8/2003 | 16/6/2026 | Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters. |