Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.97%💥 ExploitActivewebsoftwares Ewebquiz21/6/201016/6/2026
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706.
ModificadaAlta (7.5)0.97%💥 ExploitActivewebsoftwares Ewebquiz28/12/200916/6/2026
Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp, different vectors than CVE-2007-1706.
ModificadaBaja (3.5)1.00%—Drupal Quiz5/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Quiz module 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for Drupal, allows remote authenticated users, with create quizzes or quiz questions access, to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)0.96%💥 ExploitGlenn Mcgurrin Flash Quiz1/6/200916/6/2026
Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) quiz parameter to (a) num_questions.php, (b) answers.php, (c) high_score.php, (d) high_score_web.php, (e) results_table_web.php, and (f) question.php; and the (2) order_number parameter to…
ModificadaAlta (7.5)1.0%💥 ExploitWebbdomain Quiz6/4/200916/6/2026
SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (7.5)1.1%—Kurt Gusbeth Myquizpoll13/3/200916/6/2026
SQL injection vulnerability in the My quiz and poll (myquizpoll) extension before 0.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.00%💥 ExploitManzovi Proquiz27/2/200916/6/2026
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter, a different vector than CVE-2008-6312.
ModificadaAlta (7.5)1.1%💥 ExploitManzovi Proquiz27/2/200916/6/2026
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (7.5)1.00%💥 ExploitActivewebsoftwares Active Ewebquiz17/12/200816/6/2026
SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or the (2) password parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)27%💥 ExploitElearningforce Online Flashquiz4/4/200816/6/2026
PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter.
ModificadaAlta (7.5)1.00%💥 ExploitJoomla COM QuizMambo COM Quiz15/2/200816/6/2026
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.
ModificadaAlta (7.5)1.00%💥 ExploitJoomla COM Mcquiz15/2/200816/6/2026
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.
ModificadaAlta (10)1.6%💥 ExploitWire Plastic Design Wpquiz30/11/200716/6/2026
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewimage.php and (2) comments.php.
ModificadaMedia (4.3)3.6%💥 ExploitPineapple Technologies Quizshock10/4/200716/6/2026
Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<".
ModificadaAlta (7.5)1.0%💥 ExploitEwebquiz27/3/200716/6/2026
SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizID parameter.
ModificadaAlta (7.5)2.3%💥 ExploitMatthias Dietrich Phpburningportal Quiz-modul3/3/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter to (1) quest_delete.php, (2) quest_edit.php, or (3) quest_news.php.
ModificadaMedia (6.8)1.3%—Squiz Mysource ClassicSquiz Mysource Matrix27/9/200616/6/2026
MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not…
ModificadaMedia (6.8)1.3%—Squiz Mysource Matrix27/9/200616/6/2026
MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider…
ModificadaAlta (7.5)1.8%💥 ExploitWalter Beschmout Phpquiz25/9/200616/6/2026
Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the univers parameter in score.php and (2) the quiz_id parameter in home.php, accessed through the front/ URI.
ModificadaMedia (5)3.0%💥 ExploitWalter Beschmout Phpquiz25/9/200616/6/2026
Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to upload arbitrary PHP code to the phpquiz/img_quiz folder via the (a) upload, (b) ok_update, (c) image, and (d) path parameters, possibly…
ModificadaMedia (5)2.8%💥 ExploitWalter Beschmout Phpquiz25/9/200616/6/2026
Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows remote attackers to inject arbitrary PHP code in config.inc.php via modified configuration settings.
ModificadaMedia (5)5.0%💥 ExploitPhpquiz19/9/200616/6/2026
Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified vectors.
ModificadaAlta (7.5)7.9%💥 ExploitPhpquiz15/9/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in the pagename parameter.
ModificadaMedia (6.5)1.4%—Squiz Mysource Classic8/9/200616/6/2026
Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecified vectors related to the Equation attribute in Web_Extensions - Notitia (I/II). NOTE: due to lack of details, it is not clear whether this…
ModificadaMedia (4.3)2.0%💥 ExploitCaloris Planitia Technologies WEB Quiz PRO28/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in student.asp.
Orbitaley — Vulnerabilidades