Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)1.9%—PhpsysinfoAI28/8/20269/9/2026
phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can supply an allowed address in one of these…
ModificadaMedia (6.5)0.52%—Phpsysinfo19/12/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted page in the XML.php file.
ModificadaAlta (8.8)0.67%—Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+43/6/201917/6/2026
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of specific account via useradmin/cf_new.cgi?chief=&wk_group=full&cf_name=test&cf_account=test&cf_email=&cf_acl=Management&apply_lang=&dn= without any authorizes.
ModificadaAlta (8.8)0.67%—Hgiga Msr35 Isherlock-baseHgiga Msr35 Isherlock-sysinfoHgiga Msr35 Isherlock-userHgiga Msr35 Isherlock-useradmin+43/6/201917/6/2026
Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email sources into whitelist via user/save_list.php?ACSION=&type=email&category=white&locate=big5&cmd=add&new=hacker@socialengineering.com&new_memo=&add=%E6%96%B0%E5%A2%9E without any authorizes.
ModificadaMedia (5.5)0.53%—Magnicomp Sysinfo21/5/201817/6/2026
MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file permissions. Confidential information such as password…
ModificadaAlta (7.8)0.32%—Magnicomp Sysinfo30/4/201817/6/2026
An issue was discovered in MagniComp SysInfo before 10-H82 if setuid root (the default). This vulnerability allows any local user on a Linux/UNIX system to run SysInfo and obtain a root shell, which can be used to compromise the local system.
ModificadaMedia (6.7)5.3%—Magnicomp Sysinfo14/3/201717/6/2026
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain elevated privileges. Parts of SysInfo require setuid-to-root access in order to access restricted system files and make restricted kernel calls. This access could be…
ModificadaMedia (4.3)1.3%—Phpsysinfo30/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaAlta (10)3.6%—Prosysinfo Tftp Server Tftpdwin13/5/200716/6/2026
Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors.
ModificadaAlta (7.3)67%—Prosysinfo Tftp Server Tftpdwin10/3/200716/6/2026
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948.
ModificadaAlta (7.5)55%—Prosysinfo Tftp Server Tftpdwin23/9/200616/6/2026
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (5)5.6%—Phpsysinfo6/7/200616/6/2026
Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.
ModificadaAlta (7.5)8.3%—Coder-world Sysinfo19/4/200616/6/2026
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.
ModificadaMedia (5)6.6%—Coder-world Sysinfo19/4/200616/6/2026
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.
ModificadaMedia (4.3)2.0%—Phpsysinfo18/11/200516/6/2026
HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.
ModificadaMedia (4.3)3.7%—Phpsysinfo2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist parameter to system_footer.php.
ModificadaMedia (5)5.2%—Phpsysinfo2/5/200516/6/2026
phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PHP error message.
ModificadaBaja (3.6)1.5%—Phpsysinfo18/8/200316/6/2026
Directory traversal vulnerability in phpSysInfo 2.1 and earlier allows attackers with write access to a local directory to read arbitrary files as the PHP user or cause a denial of service via .. (dot dot) sequences in the (1) template or (2) lng parameters.