Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | 2daybiz WEB Template Software | 28/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Shape5 Bridge OF Hope Template | 9/6/2010 | 16/6/2026 | SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Templateplazza COM Tpjobs | 16/3/2010 | 16/6/2026 | SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Templateplaza COM Tpdugg | 18/1/2010 | 16/6/2026 | SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php. | |
| Modificada | Media (5) | 2.1% | 💥 Exploit | 2daybiz Template Monster Clone | 22/5/2009 | 16/6/2026 | admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Aspapps Template Creature | 23/1/2009 | 16/6/2026 | ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Aspapps Template Creature | 23/1/2009 | 16/6/2026 | SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Awesometemplateengine | 10/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Codewidgets Online Event Registration Template | 29/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Deonixscripts WEB Template Management System | 5/10/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Codewidgets Online Event Registration Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Codewidgets Online Event Registration Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Codewidgets Real Estate Listing Website Application Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Alta (10) | 8.6% | 💥 Exploit | Alstrasoft Template Seller | 21/5/2007 | 16/6/2026 | AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Alstrasoft Template Seller | 21/5/2007 | 16/6/2026 | Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Bonoestente Joomla Template Be2004-2 | 19/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Alstrasoft Template Seller | 6/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Alstrasoft Template Seller | 16/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Infinetsoftware Mytemplatesite | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Scripts-templates Allweb Search | 29/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Alstrasoft Template Seller | 24/11/2005 | 16/6/2026 | SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commands via the username field. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Alstrasoft Template Seller | 24/11/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter. |