Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 0.90% | 💥 Exploit | Duware Duclassified | 1/5/2006 | 16/6/2026 | SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.3% | — | Deltascripts PHP Classifieds | 30/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Fusionzone Classifiedzone | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter. | |
| Modificada | Media (6.4) | 1.6% | — | Phpoutsourcing Noahs Classifieds | 21/3/2006 | 16/6/2026 | Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error message. | |
| Modificada | Media (6.8) | 1.4% | — | Phpoutsourcing Noahs Classifieds | 21/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors. | |
| Modificada | Media (5) | 1.5% | — | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Deltascripts PHP Classifieds | 15/2/2006 | 16/6/2026 | SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Almondsoft Almond ClassifiedsAI | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Locazolist Classifieds | 13/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Xcent Xcclassified | 7/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CPSearch.asp in XcClassified 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameters. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Scriptdevelopers.net Netclassifieds | 3/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c)… | |
| Modificada | Alta (7.5) | 1.2% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 3/12/2005 | 16/6/2026 | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote… | |
| Modificada | Alta (7.5) | 1.1% | — | Almondsoft Almond Classifieds | 22/11/2005 | 16/6/2026 | Almond Classifieds does not properly verify the password, which allows attackers to bypass access restrictions. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Unclassified Newsboard | 19/11/2005 | 16/6/2026 | SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 20/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 20/9/2005 | 16/6/2026 | SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Unclassified Newsboard | 8/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field. | |
| Modificada | Alta (10) | 4.2% | — | Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+2 | 13/7/2005 | 16/6/2026 | The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the… | |
| Modificada | Media (4.3) | 1.9% | — | Duware Duclassified | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in DUware DUclassified 4.0 allows remote attackers to inject arbitrary web script or HTML via the message text. | |
| Modificada | Alta (7.5) | 1.5% | 💥 Exploit | Duware Duclassified | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authentication and execute other commands on the server's underlying database via the (1) cat_id or (2) sub_id parameters in adDetail.asp, or (2) the password parameter in the login form. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Fuzzymonkey Myclassifieds | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter. |