Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.41%—E-learning PHP ScriptAI30/1/202617/6/2026
e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information.
AplazadaMedia (5.1)0.40%—Pharmacy POS PHP ScriptAI16/7/202517/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the u_medicine_name parameter in /edit_medicine.php. This vulnerability can be exploited to steal sensitive…
ModificadaCrítica (9.8)1.7%—Superstorefinder PHP Script14/9/202317/6/2026
SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter.
ModificadaMedia (6.1)0.36%—Gzscripts CAR Rental PHP Script19/7/202317/6/2026
A vulnerability classified as problematic has been found in GZ Scripts Car Rental Script 1.8. Affected is an unknown function of the file /EventBookingCalendar/load.php?controller=GzFront/action=checkout/cid=1/layout=calendar/show_header=T/local=3. The manipulation of the argument…
ModificadaCrítica (9.8)1.2%—KB Messages PHP Script Project KB Messages PHP Script13/7/202217/6/2026
A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)3.0%💥 ExploitDomainsale PHP Script Project Domainsale PHP Script13/12/201717/6/2026
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.
ModificadaCrítica (9.8)2.7%💥 ExploitArox School ERP PHP Script31/10/201717/6/2026
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
ModificadaMedia (6.8)2.3%💥 ExploitPhpscriptlerim PHP Scriptlerim Who's WHO17/11/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the authentication of administrators or requests that (1) add an admin account via a request to filepath/yonetim/plugin/adminsave.php or have unspecified impact via a request to (2)…
ModificadaAlta (7.5)1.2%—Real-estate-php-script Real Estate PHP Script23/9/201316/6/2026
SQL injection vulnerability in property_listings_detail.php in Real Estate PHP Script allows remote attackers to execute arbitrary SQL commands via the listingid parameter.
ModificadaMedia (4.3)0.98%—Real-estate-php-script Real Estate PHP Script23/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in search_residential.php in Real Estate PHP Script allows remote attackers to inject arbitrary web script or HTML via the bos parameter.
ModificadaMedia (5)2.8%💥 ExploitPhp4scripte Gastebuch12/9/201116/6/2026
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.
ModificadaAlta (7.5)5.6%💥 ExploitMoviephp Movie PHP Script6/5/201016/6/2026
Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter.
ModificadaAlta (7.5)2.9%💥 ExploitSansuart Free Simple Guestbook PHP Script11/8/200916/6/2026
Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some…
ModificadaAlta (7.5)2.6%💥 ExploitMarc Melvin A+ PHP Scripts News Management System8/4/200916/6/2026
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.
ModificadaAlta (7.5)1.2%💥 ExploitSeraphimtech Free Bible Search PHP Script29/1/200916/6/2026
SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter.
ModificadaAlta (7.5)1.0%💥 ExploitE-topbiz Number Links 1 PHP Script31/12/200816/6/2026
SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.
ModificadaMedia (4.3)1.2%💥 ExploitSimple PHP Scripts Gallery31/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)0.87%—Simple PHP Scripts Blog31/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in complete.php in Simple PHP Scripts blog 0.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitE-php Scripts B2B Trading Marketplace Script7/10/200816/6/2026
SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute arbitrary SQL commands via the cid parameter in a product action.
ModificadaAlta (7.5)3.0%💥 ExploitRaven PHP Scripts Keep IT Simple Guest Book2/4/200816/6/2026
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.
ModificadaAlta (7.8)8.5%💥 ExploitJustin Hagstrom Autoindex PHP Script15/11/200716/6/2026
classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via a %00 sequence in the dir parameter to index.php, which triggers an erroneous "recursive calculation."
ModificadaMedia (4.3)2.0%💥 ExploitJustin Hagstrom Autoindex PHP Script15/11/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF).
ModificadaMedia (6.8)1.3%—Simple PHP Scripts Gallery15/5/200716/6/2026
PHP file inclusion vulnerability in index.php in Ivan Peevski gallery 0.3 in Simple PHP Scripts (sphp) allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the gallery parameter, which is accessed by the file_exists function. NOTE: the provenance of this…
ModificadaAlta (7.5)1.1%—Free PHP Scripts Schoolboard11/5/200716/6/2026
SQL injection vulnerability in admin.php in SchoolBoard allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: CVE disputes this issue, because 'username' does not exist, and the password is not used in any queries
ModificadaAlta (7.5)2.4%💥 ExploitFree PHP Scripts Free Image Hosting27/3/200716/6/2026
PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763.
Orbitaley — Vulnerabilidades