Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

322 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.3%💥 ExploitPodcast Generator2/4/200916/6/2026
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.
ModificadaAlta (7.5)2.9%💥 ExploitSocialsitegenerator Social Site Generator6/3/200916/6/2026
PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
ModificadaMedia (5)3.6%💥 ExploitSocialsitegenerator Social Site Generator6/3/200916/6/2026
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php, and (3) webadmin/download_file.php.
ModificadaAlta (7.5)1.2%💥 ExploitSocialsitegenerator Social Site Generator6/3/200916/6/2026
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) sgc_id parameter to display_blog.php, (2) scm_mem_id parameter to social_my_profile_download.php, and the (3) catid parameter to social_forum_subcategories.php.
ModificadaMedia (5)1.2%—Typo3 PDF Generator 2 Extension7/7/200816/6/2026
Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to cause a denial of service via unspecified vectors.
ModificadaMedia (5)1.0%—Typo3 PDF Generator 2 Extension7/7/200816/6/2026
The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors.
ModificadaAlta (7.5)1.1%—Typo3 PDF Generator 2 Extension7/7/200816/6/2026
Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 has unknown impact and attack vectors related to "Unprotected test functionality."
ModificadaAlta (10)3.8%—Sarg Squid Analysis Report Generator13/5/200816/6/2026
Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.
ModificadaMedia (4.3)0.84%—Podcast Generator8/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in set_permissions.php in Podcast Generator 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the scriptlang parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (10)6.7%—Sarg Squid Analysis Report Generator5/3/200816/6/2026
Stack-based buffer overflow in the useragent function in useragent.c in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to execute arbitrary code via a long Squid proxy server User-Agent header. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.6%—Sarg Squid Analysis Report Generator5/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are…
ModificadaMedia (5)3.1%💥 ExploitPodcast Generator3/3/200816/6/2026
Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) theme_path parameter to core/themes.php and the (2) filename parameter to download.php.
ModificadaMedia (6.8)22%💥 ExploitPodcast Generator3/3/200816/6/2026
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) components/xmlparser/loadparser.php; (2) admin.php, (3) categories.php, (4) categories_add.php, (5) categories_remove.php,…
ModificadaAlta (10)4.8%💥 ExploitVirtualsystem Htaccess Passwort Generator21/2/200716/6/2026
PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter.
ModificadaAlta (7.5)1.8%—PHP Animated Smiley Generator14/12/200616/6/2026
PHP remote file inclusion vulnerability in signer/final.php in warez distributions of Animated Smiley Generator allows remote attackers to execute arbitrary PHP code via a URL in the smiley parameter. NOTE: the vendor disputes this issue, stating that only Warez versions of Animated Smiley Generator were affected, not…
ModificadaAlta (7.5)1.2%💥 ExploitASP Stats Generator13/7/200616/6/2026
SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.
ModificadaMedia (4)2.3%💥 ExploitASP Stats Generator23/6/200616/6/2026
Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp.
ModificadaBaja (2.6)1.8%💥 ExploitAweb Banner Generator11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode.
ModificadaMedia (6.5)2.3%💥 ExploitFree Host Shop Website Generator28/2/200616/6/2026
Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.
ModificadaMedia (4.3)1.2%—Hitachi WEB Page GeneratorHitachi WEB Page Generator Enterprise31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
ModificadaMedia (5)1.4%—Hitachi WEB Page GeneratorAIHitachi WEB Page Generator EnterpriseAI31/12/200416/6/2026
Unspecified vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to determine internal directory structures via unknown attack vectors.
ModificadaAlta (7.8)1.8%—Hitachi WEB Page GeneratorAIHitachi WEB Page Generator EnterpriseAI31/12/200416/6/2026
Unspecified vulnerability in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier allows remote attackers to cause a denial of service via unknown attack vectors when a web site is "improperly accessed."
Orbitaley — Vulnerabilidades