Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

254 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)0.90%💥 ExploitDuware Duclassified1/5/200616/6/2026
SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.3%—Deltascripts PHP Classifieds30/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter.
ModificadaMedia (4.3)1.9%💥 ExploitFusionzone Classifiedzone28/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter.
ModificadaMedia (6.4)1.6%—Phpoutsourcing Noahs Classifieds21/3/200616/6/2026
Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error message.
ModificadaMedia (6.8)1.4%—Phpoutsourcing Noahs Classifieds21/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter.
ModificadaAlta (7.5)1.3%💥 ExploitPhpoutsourcing Noahs Classifieds24/2/200616/6/2026
SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.
ModificadaMedia (5)1.5%—Phpoutsourcing Noahs Classifieds24/2/200616/6/2026
Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php.
ModificadaMedia (4.3)1.9%💥 ExploitPhpoutsourcing Noahs Classifieds24/2/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters.
ModificadaAlta (7.5)7.7%💥 ExploitPhpoutsourcing Noahs Classifieds24/2/200616/6/2026
Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.
ModificadaMedia (5)2.8%💥 ExploitPhpoutsourcing Noahs Classifieds24/2/200616/6/2026
Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.
ModificadaAlta (7.5)1.3%💥 ExploitDeltascripts PHP Classifieds15/2/200616/6/2026
SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.
ModificadaAlta (7.5)1.2%—Almondsoft Almond ClassifiedsAI17/12/200516/6/2026
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.8%💥 ExploitLocazolist Classifieds13/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (4.3)1.2%—Xcent Xcclassified7/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters.
ModificadaAlta (7.5)2.7%💥 ExploitScriptdevelopers.net Netclassifieds3/12/200516/6/2026
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c)…
ModificadaAlta (7.5)1.2%—Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+73/12/200516/6/2026
SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote…
ModificadaAlta (7.5)1.1%—Almondsoft Almond Classifieds22/11/200516/6/2026
Almond Classifieds does not properly verify the password, which allows attackers to bypass access restrictions.
ModificadaAlta (7.5)1.3%💥 ExploitUnclassified Newsboard19/11/200516/6/2026
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.
ModificadaMedia (4.3)1.8%💥 ExploitPhpoutsourcing Noahs Classifieds20/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter.
ModificadaAlta (7.5)1.2%💥 ExploitPhpoutsourcing Noahs Classifieds20/9/200516/6/2026
SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter.
ModificadaMedia (4.3)2.0%💥 ExploitUnclassified Newsboard8/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field.
ModificadaAlta (10)4.2%—Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+213/7/200516/6/2026
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the…
ModificadaMedia (4.3)1.9%—Duware Duclassified31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the message text.
ModificadaAlta (7.5)1.5%💥 ExploitDuware Duclassified31/12/200416/6/2026
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form.
ModificadaMedia (6.8)1.1%💥 ExploitFuzzymonkey Myclassifieds31/12/200316/6/2026
SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.
Orbitaley — Vulnerabilidades