Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.6%💥 ExploitAlstrasoft Template Seller6/9/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php.
ModificadaMedia (4.3)1.7%💥 ExploitAlstrasoft Template Seller16/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.
ModificadaMedia (4.3)1.2%—Infinetsoftware Mytemplatesite5/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in MyTemplateSite 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaAlta (7.5)2.4%💥 ExploitScripts-templates Allweb Search29/11/200516/6/2026
SQL injection vulnerability in index.php in AllWeb search 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter.
ModificadaAlta (7.5)1.4%—Alstrasoft Template Seller24/11/200516/6/2026
SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commands via the username field.
ModificadaAlta (7.5)3.8%💥 ExploitAlstrasoft Template Seller24/11/200516/6/2026
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter.
ModificadaAlta (7.5)1.1%—Deplate24/3/200516/6/2026
Unknown vulnerabilities in deplate before 0.7.2 have unknown impact, possibly involving elements.rb.