Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Activewebsoftwares Ewebquiz | 21/6/2010 | 16/6/2026 | SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Activewebsoftwares Ewebquiz | 28/12/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp, different vectors than CVE-2007-1706. | |
| Modificada | Baja (3.5) | 1.00% | — | Drupal Quiz | 5/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Quiz module 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for Drupal, allows remote authenticated users, with create quizzes or quiz questions access, to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Glenn Mcgurrin Flash Quiz | 1/6/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) quiz parameter to (a) num_questions.php, (b) answers.php, (c) high_score.php, (d) high_score_web.php, (e) results_table_web.php, and (f) question.php; and the (2) order_number parameter to… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Webbdomain Quiz | 6/4/2009 | 16/6/2026 | SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Kurt Gusbeth Myquizpoll | 13/3/2009 | 16/6/2026 | SQL injection vulnerability in the My quiz and poll (myquizpoll) extension before 0.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Manzovi Proquiz | 27/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the password parameter, a different vector than CVE-2008-6312. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Manzovi Proquiz | 27/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Activewebsoftwares Active Ewebquiz | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in start.asp in Active eWebquiz 8.0 allows remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or the (2) password parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 27% | 💥 Exploit | Elearningforce Online Flashquiz | 4/4/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Joomla COM QuizMambo COM Quiz | 15/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Joomla COM Mcquiz | 15/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action. | |
| Modificada | Alta (10) | 1.6% | 💥 Exploit | Wire Plastic Design Wpquiz | 30/11/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewimage.php and (2) comments.php. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Pineapple Technologies Quizshock | 10/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in auth.php in Pineapple Technologies QuizShock 1.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via encoded special characters in the forward_to parameter, as demonstrated using "<"<". | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Ewebquiz | 27/3/2007 | 16/6/2026 | SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizID parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Matthias Dietrich Phpburningportal Quiz-modul | 3/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter to (1) quest_delete.php, (2) quest_edit.php, or (3) quest_news.php. | |
| Modificada | Media (6.8) | 1.3% | — | Squiz Mysource ClassicSquiz Mysource Matrix | 27/9/2006 | 16/6/2026 | MySource Matrix 3.8 and earlier, and MySource 2.x, allow remote attackers to use the application as an HTTP proxy server via the sq_remote_page_url parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not… | |
| Modificada | Media (6.8) | 1.3% | — | Squiz Mysource Matrix | 27/9/2006 | 16/6/2026 | MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks. NOTE: the researcher reports that "The vendor does not consider… | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Walter Beschmout Phpquiz | 25/9/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the univers parameter in score.php and (2) the quiz_id parameter in home.php, accessed through the front/ URI. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Walter Beschmout Phpquiz | 25/9/2006 | 16/6/2026 | Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to upload arbitrary PHP code to the phpquiz/img_quiz folder via the (a) upload, (b) ok_update, (c) image, and (d) path parameters, possibly… | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Walter Beschmout Phpquiz | 25/9/2006 | 16/6/2026 | Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows remote attackers to inject arbitrary PHP code in config.inc.php via modified configuration settings. | |
| Modificada | Media (5) | 5.0% | 💥 Exploit | Phpquiz | 19/9/2006 | 16/6/2026 | Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified vectors. | |
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | Phpquiz | 15/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in the pagename parameter. | |
| Modificada | Media (6.5) | 1.4% | — | Squiz Mysource Classic | 8/9/2006 | 16/6/2026 | Unspecified vulnerability in MySource Classic 2.14.6, and possibly earlier, allows remote authenticated users, with superuser privileges, to inject arbitrary PHP code via unspecified vectors related to the Equation attribute in Web_Extensions - Notitia (I/II). NOTE: due to lack of details, it is not clear whether this… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Caloris Planitia Technologies WEB Quiz PRO | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Caloris Planitia Online Quiz System (aka Web Quiz pro), possibly 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) exam parameter in prequiz.asp or (2) msg parameter in student.asp. |