Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.5%—Limesurvey21/7/201417/6/2026
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.
ModificadaAlta (7.5)1.9%—Limesurvey21/7/201417/6/2026
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter.
ModificadaMedia (4.3)1.5%—Limesurvey21/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to…
ModificadaBaja (2.6)0.90%—Limesurvey12/2/201316/6/2026
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.
ModificadaMedia (4.3)1.2%—Limesurvey19/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.5)1.0%—Limesurvey19/9/201216/6/2026
SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)2.2%💥 ExploitLimesurvey15/9/201216/6/2026
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php.
ModificadaMedia (4.3)1.5%💥 ExploitSellatsite Smart ASP Survey2/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter.
ModificadaMedia (5)1.3%—Limesurvey23/9/201116/6/2026
LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files.
ModificadaAlta (9.3)45%💥 ExploitVisiwave Site Survey8/6/201116/6/2026
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference.
ModificadaMedia (4.3)1.9%—Fubra Wp-survey-and-quiz-tool30/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaAlta (7.5)18%💥 ExploitTamlyncreative COM Bfsurvey ProfreeTamlyncreative COM Bfsurvey PROTamlyncreative COM Bfsurvey Basic9/6/201016/6/2026
Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)1.0%💥 ExploitTamlyncreative COM Bfsurvey ProfreeTamlyncreative COM Bfsurvey PROTamlyncreative COM Bfsurvey Basic9/6/201016/6/2026
SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these…
ModificadaAlta (7.5)2.4%💥 ExploitTamlyncreative COM Bfsurvey Profree18/1/201016/6/2026
SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage…
ModificadaAlta (7.5)0.96%💥 ExploitFocusdev COM Surveymanager23/9/200916/6/2026
SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.
ModificadaAlta (7.5)0.99%💥 ExploitSellatsite.com Smart ASP Survey14/8/200916/6/2026
SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaAlta (7.5)1.8%—Limesurvey11/5/200916/6/2026
Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/.
ModificadaAlta (7.5)0.97%💥 ExploitTurnkeyforms Business Survey PRO2/3/200916/6/2026
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.1%—Typo3 Simplesurvey22/10/200816/6/2026
SQL injection vulnerability in the Simple survey (simplesurvey) 1.7.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.5%💥 ExploitJandus Technologies Smart Survey11/9/200816/6/2026
Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitPreproject PRE Survey Poll25/7/200816/6/2026
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaMedia (4.3)1.1%—Limesurvey6/6/200816/6/2026
Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.
ModificadaAlta (9.3)1.3%—Limesurvey6/6/200816/6/2026
Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.
ModificadaMedia (4.3)1.1%—Bluemoon BackpackBluemoon BmsurveyBluemoon Newbb FileupBluemoon News Fileup+330/4/200816/6/2026
Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote…
ModificadaMedia (6.8)2.6%💥 ExploitLimesurvey18/10/200716/6/2026
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.