Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.0%💥 ExploitTemplate CMS Project Template CMS20/5/201516/6/2026
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the themes_editor parameter in an add_template action to admin/index.php.
ModificadaMedia (5)1.8%—Pyplate7/8/201417/6/2026
Directory traversal vulnerability in download.py in Pyplate 0.08 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
ModificadaMedia (6.8)0.94%💥 ExploitPyplate7/8/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter.
ModificadaMedia (5)1.3%—Pyplate7/8/201417/6/2026
Pyplate 0.08 does not set the secure flag for the id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
ModificadaMedia (5)1.6%—Pyplate7/8/201417/6/2026
Pyplate 0.08 does not include the HTTPOnly flag in a Set-Cookie header for the id cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
ModificadaBaja (2.1)0.40%—Pyplate7/8/201417/6/2026
usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the administrator password by reading this file.
ModificadaMedia (4.3)1.6%—Igor Vlasenko Html-template-pro6/1/201216/6/2026
Cross-site scripting (XSS) vulnerability in the HTML-Template-Pro module before 0.9507 for Perl allows remote attackers to inject arbitrary web script or HTML via template parameters, related to improper handling of > (greater than) and < (less than) characters.
ModificadaMedia (4.3)1.8%—Makotemplates Mako2/7/201016/6/2026
Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.
ModificadaAlta (7.5)0.91%💥 Exploit2daybiz WEB Template Software28/6/201016/6/2026
SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter.
ModificadaMedia (4.3)1.3%💥 Exploit2daybiz WEB Template Software28/6/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php.
ModificadaAlta (7.5)0.97%💥 ExploitShape5 Bridge OF Hope Template9/6/201016/6/2026
SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.
ModificadaAlta (7.5)1.2%💥 ExploitTemplateplazza COM Tpjobs16/3/201016/6/2026
SQL injection vulnerability in the TPJobs (com_tpjobs) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_c[] parameter in a resadvsearch action to index.php.
ModificadaAlta (7.5)1.6%💥 ExploitTemplateplaza COM Tpdugg18/1/201016/6/2026
SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.
ModificadaMedia (5)2.1%💥 Exploit2daybiz Template Monster Clone22/5/200916/6/2026
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
ModificadaMedia (5)2.2%💥 ExploitAspapps Template Creature23/1/200916/6/2026
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb.
ModificadaAlta (7.5)0.97%💥 ExploitAspapps Template Creature23/1/200916/6/2026
SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter.
ModificadaMedia (4.3)1.8%💥 ExploitAwesometemplateengine10/1/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in templates/example_template.php in AwesomeTemplateEngine allow remote attackers to inject arbitrary web script or HTML via the (1) data[title], (2) data[message], (3) data[table][1][item], (4) data[table][1][url], or (5) data[poweredby] parameter.
ModificadaAlta (7.5)1.3%—Codewidgets Online Event Registration Template29/10/200716/6/2026
Multiple SQL injection vulnerabilities in CodeWidgets.com Online Event Registration Template allow remote attackers to execute arbitrary SQL commands via the (1) Email Address and (2) Password fields in (a) login.asp and (b) admin_login.asp.
ModificadaAlta (7.5)1.0%💥 ExploitDeonixscripts WEB Template Management System5/10/200716/6/2026
SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a readmore action.
ModificadaMedia (6.8)1.1%💥 ExploitCodewidgets Real Estate Listing Website Application Template31/7/200716/6/2026
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (7.5)1.2%💥 ExploitCodewidgets Online Event Registration Template31/7/200716/6/2026
SQL injection vulnerability in sign_in.aspx in WebStore (Online Store Application Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (7.5)1.3%—Codewidgets Online Event Registration Template31/7/200716/6/2026
SQL injection vulnerability in sign_in.aspx in WebEvents (Online Event Registration Template) allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (10)8.6%💥 ExploitAlstrasoft Template Seller21/5/200716/6/2026
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php.
ModificadaAlta (7.5)6.3%💥 ExploitAlstrasoft Template Seller21/5/200716/6/2026
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.
ModificadaAlta (7.5)2.4%💥 ExploitBonoestente Joomla Template Be2004-219/4/200716/6/2026
PHP remote file inclusion vulnerability in index.php in the Be2004-2 template for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Orbitaley — Vulnerabilidades