Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

312 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.85%—Xzeroscripts Xzero Community Classifieds21/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.5%💥 ExploitXzeroscripts Xzero Community Classifieds20/8/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter.
ModificadaAlta (7.5)6.1%💥 Exploit2daybiz Business Community Script16/5/200916/6/2026
admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.
ModificadaAlta (7.5)2.0%💥 Exploit2daybiz Business Community Script16/5/200916/6/2026
SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.
ModificadaAlta (7.5)1.1%💥 ExploitCommunity CMS3/2/200916/6/2026
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM ComprofilerJoomlapolis Community BuilderMambo COM Comprofiler6/5/200816/6/2026
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.
ModificadaMedia (6.5)1.3%—Mysql Community Server18/2/200816/6/2026
MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements.
ModificadaAlta (7.5)2.3%💥 ExploitXzero Scripts Xzero Community Classifieds28/12/200716/6/2026
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.
ModificadaMedia (6.4)7.0%💥 ExploitXzero Scripts Xzero Community Classifieds28/12/200716/6/2026
Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action.
ModificadaAlta (7.5)2.4%💥 ExploitXzero Scripts Xzero Community Classifieds28/12/200716/6/2026
SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php.
ModificadaAlta (7.1)14%—Mysql ServerMysql Community ServerMysql Enterprise Server10/12/200716/6/2026
MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and…
ModificadaMedia (4.3)1.1%—Blackboard Learning AND Community Post Systems5/10/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in messaging/course/composeMessage.jsp in BlackBoard Learning System 6.3.1.593 and earlier in BlackBoard Academic Suite allow remote attackers to inject arbitrary web script or HTML via the (1) subject_t and (2) body_text parameters. NOTE: vector 2 requires bypassing…
ModificadaMedia (5)14%—Mysql Community Server15/7/200716/6/2026
MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol.
ModificadaMedia (4)1.8%—Mysql Community Server15/7/200716/6/2026
MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure.
ModificadaBaja (3.5)1.6%—Mysql Community Server15/7/200716/6/2026
MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table.
ModificadaAlta (7.5)2.3%💥 ExploitCuttlefish Leicestershire Communityportals7/3/200716/6/2026
PHP remote file inclusion vulnerability in bug.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280. NOTE: CVE disputes this issue, since bug.php is not in…
ModificadaAlta (7.5)6.1%💥 ExploitCliserv WEB Community2/3/200716/6/2026
PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cl_headers parameter to (1) menu.php3 and (2) login.php3.
ModificadaMedia (4.3)1.6%💥 ExploitCommunityserver.org Community Server14/2/200716/6/2026
Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (5)1.5%—Telligent Systems Community Server Forums29/1/200716/6/2026
Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content…
ModificadaAlta (7.8)3.0%💥 ExploitArsdigita Community Education SolutionArsdigita Community System19/1/200716/6/2026
Directory traversal vulnerability in ArsDigita Community System (ACS) 3.4.10 and earlier, and ArsDigita Community Education Solution (ACES) 1.1, allows remote attackers to read arbitrary files via .%252e/ (double-encoded dot dot slash) sequences in the URI.
ModificadaAlta (7.5)1.1%💥 ExploitInvision Power Services Invision Community Blog7/12/200616/6/2026
SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.
ModificadaAlta (7.5)1.8%💥 ExploitDynamic Dataworx Nucommunity14/11/200616/6/2026
SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter.
ModificadaAlta (7.5)2.2%💥 ExploitLeicestershire Communityportals6/11/200616/6/2026
PHP remote file inclusion vulnerability in cpadmin/cpa_index.php in Leicestershire communityPortals 1.0_2005-10-18_12-31-18 allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter, a different vector than CVE-2006-5280.
ModificadaMedia (6.8)1.9%—Cuttlefish Multimedia Ltd. Leicestershire Communityportals13/10/200616/6/2026
PHP remote file inclusion vulnerability in includes/import-archive.php in Leicestershire communityPortals 1.0 build 20051018 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cp_root_path parameter.
ModificadaMedia (5.1)1.4%—Wired Community Software Wwwthreads28/9/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WWWthreads 5.4.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the Cat parameter to (1) dosearch.php, (2) postlist.php, (3) showmembers.php, (4) faq_english.php, (5) online.php, (6) login.php, (7) newuser.php, (8) wwwthreads.php,…
Orbitaley — Vulnerabilidades