Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

247 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%💥 Exploit2daybiz WEB Template Software28/6/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php.
ModificadaAlta (7.5)0.97%💥 ExploitShape5 Bridge OF Hope Template9/6/201016/6/2026
SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.
ModificadaAlta (7.5)1.2%💥 ExploitTemplateplazza COM Tpjobs16/3/201016/6/2026
SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php.
ModificadaAlta (7.5)1.6%💥 ExploitTemplateplaza COM Tpdugg18/1/201016/6/2026
SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.
ModificadaMedia (5)2.1%💥 Exploit2daybiz Template Monster Clone22/5/200916/6/2026
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
ModificadaMedia (5)2.2%💥 ExploitAspapps Template Creature23/1/200916/6/2026
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb.
ModificadaAlta (7.5)0.97%💥 ExploitAspapps Template Creature23/1/200916/6/2026
SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter.
ModificadaMedia (4.3)1.8%💥 ExploitAwesometemplateengine10/1/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter.
ModificadaAlta (7.5)1.3%—Codewidgets Online Event Registration Template29/10/200716/6/2026
Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp.
ModificadaAlta (7.5)1.0%💥 ExploitDeonixscripts WEB Template Management System5/10/200716/6/2026
SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action.
ModificadaAlta (7.5)1.2%💥 ExploitCodewidgets Online Event Registration Template31/7/200716/6/2026
SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (7.5)1.3%—Codewidgets Online Event Registration Template31/7/200716/6/2026
SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaMedia (6.8)1.1%💥 ExploitCodewidgets Real Estate Listing Website Application Template31/7/200716/6/2026
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (10)8.6%💥 ExploitAlstrasoft Template Seller21/5/200716/6/2026
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.
ModificadaAlta (7.5)6.3%💥 ExploitAlstrasoft Template Seller21/5/200716/6/2026
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.
ModificadaAlta (7.5)2.4%💥 ExploitBonoestente Joomla Template Be2004-219/4/200716/6/2026
PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
ModificadaAlta (7.5)2.6%💥 ExploitAlstrasoft Template Seller6/9/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php.
ModificadaMedia (4.3)1.7%💥 ExploitAlstrasoft Template Seller16/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.
ModificadaMedia (4.3)1.2%—Infinetsoftware Mytemplatesite5/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaAlta (7.5)2.4%💥 ExploitScripts-templates Allweb Search29/11/200516/6/2026
SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter.
ModificadaAlta (7.5)1.4%—Alstrasoft Template Seller24/11/200516/6/2026
SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commands via the username field.
ModificadaAlta (7.5)3.8%💥 ExploitAlstrasoft Template Seller24/11/200516/6/2026
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter.