Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | — | Limesurvey | 21/7/2014 | 17/6/2026 | Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume. | |
| Modificada | Alta (7.5) | 1.9% | — | Limesurvey | 21/7/2014 | 17/6/2026 | SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Limesurvey | 21/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to… | |
| Modificada | Baja (2.6) | 0.90% | — | Limesurvey | 12/2/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters. | |
| Modificada | Media (4.3) | 1.2% | — | Limesurvey | 19/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/userrighthandling.php in LimeSurvey before 1.91+ Build 120224 allows remote attackers to inject arbitrary web script or HTML via the full_name parameter in a moduser action to admin/admin.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.5) | 1.0% | — | Limesurvey | 19/9/2012 | 16/6/2026 | SQL injection vulnerability in admin/admin.php in LimeSurvey before 1.91+ Build 120224 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a browse action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Limesurvey | 15/9/2012 | 16/6/2026 | SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attackers to execute arbitrary SQL commands via the fieldnames parameter to index.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Sellatsite Smart ASP Survey | 2/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in poll/default.asp in Smart ASP Survey allows remote attackers to inject arbitrary web script or HTML via the catid parameter. | |
| Modificada | Media (5) | 1.3% | — | Limesurvey | 23/9/2011 | 16/6/2026 | LimeSurvey 1.90+ build9642-20101214 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/statistics.php and certain other files. | |
| Modificada | Alta (9.3) | 45% | 💥 Exploit | Visiwave Site Survey | 8/6/2011 | 16/6/2026 | VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to execute arbitrary code via a (1) vws and (2) vwr file with an invalid Type property, which triggers an untrusted pointer dereference. | |
| Modificada | Media (4.3) | 1.9% | — | Fubra Wp-survey-and-quiz-tool | 30/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Alta (7.5) | 18% | 💥 Exploit | Tamlyncreative COM Bfsurvey ProfreeTamlyncreative COM Bfsurvey PROTamlyncreative COM Bfsurvey Basic | 9/6/2010 | 16/6/2026 | Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Tamlyncreative COM Bfsurvey ProfreeTamlyncreative COM Bfsurvey PROTamlyncreative COM Bfsurvey Basic | 9/6/2010 | 16/6/2026 | SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Tamlyncreative COM Bfsurvey Profree | 18/1/2010 | 16/6/2026 | SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage… | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Focusdev COM Surveymanager | 23/9/2009 | 16/6/2026 | SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Sellatsite.com Smart ASP Survey | 14/8/2009 | 16/6/2026 | SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Limesurvey | 11/5/2009 | 16/6/2026 | Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Turnkeyforms Business Survey PRO | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 Simplesurvey | 22/10/2008 | 16/6/2026 | SQL injection vulnerability in the Simple survey (simplesurvey) 1.7.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Jandus Technologies Smart Survey | 11/9/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Preproject PRE Survey Poll | 25/7/2008 | 16/6/2026 | SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Limesurvey | 6/6/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action. | |
| Modificada | Alta (9.3) | 1.3% | — | Limesurvey | 6/6/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Bluemoon BackpackBluemoon BmsurveyBluemoon Newbb FileupBluemoon News Fileup+3 | 30/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote… | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Limesurvey | 18/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter. |