Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Podcast Generator | 2/4/2009 | 16/6/2026 | core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Socialsitegenerator Social Site Generator | 6/3/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Socialsitegenerator Social Site Generator | 6/3/2009 | 16/6/2026 | Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php, and (3) webadmin/download_file.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Socialsitegenerator Social Site Generator | 6/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) sgc_id parameter to display_blog.php, (2) scm_mem_id parameter to social_my_profile_download.php, and the (3) catid parameter to social_forum_subcategories.php. | |
| Modificada | Media (5) | 1.2% | — | Typo3 PDF Generator 2 Extension | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Media (5) | 1.0% | — | Typo3 PDF Generator 2 Extension | 7/7/2008 | 16/6/2026 | The PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 allows attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 PDF Generator 2 Extension | 7/7/2008 | 16/6/2026 | Unspecified vulnerability in the PDF Generator 2 (pdf_generator2) extension 0.5.0 and earlier for TYPO3 has unknown impact and attack vectors related to "Unprotected test functionality." | |
| Modificada | Alta (10) | 3.8% | — | Sarg Squid Analysis Report Generator | 13/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file. | |
| Modificada | Media (4.3) | 0.84% | — | Podcast Generator | 8/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in set_permissions.php in Podcast Generator 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the scriptlang parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (10) | 6.7% | — | Sarg Squid Analysis Report Generator | 5/3/2008 | 16/6/2026 | Stack-based buffer overflow in the useragent function in useragent.c in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to execute arbitrary code via a long Squid proxy server User-Agent header. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.6% | — | Sarg Squid Analysis Report Generator | 5/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Podcast Generator | 3/3/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) theme_path parameter to core/themes.php and the (2) filename parameter to download.php. | |
| Modificada | Media (6.8) | 22% | 💥 Exploit | Podcast Generator | 3/3/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) components/xmlparser/loadparser.php; (2) admin.php, (3) categories.php, (4) categories_add.php, (5) categories_remove.php,… | |
| Modificada | Alta (10) | 4.8% | 💥 Exploit | Virtualsystem Htaccess Passwort Generator | 21/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the ht_pfad parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | PHP Animated Smiley Generator | 14/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in signer/final.php in warez distributions of Animated Smiley Generator allows remote attackers to execute arbitrary PHP code via a URL in the smiley parameter. NOTE: the vendor disputes this issue, stating that only Warez versions of Animated Smiley Generator were affected, not… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | ASP Stats Generator | 13/7/2006 | 16/6/2026 | SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter. | |
| Modificada | Media (4) | 2.3% | 💥 Exploit | ASP Stats Generator | 23/6/2006 | 16/6/2026 | Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp. | |
| Modificada | Baja (2.6) | 1.8% | 💥 Exploit | Aweb Banner Generator | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode. | |
| Modificada | Media (6.5) | 2.3% | 💥 Exploit | Free Host Shop Website Generator | 28/2/2006 | 16/6/2026 | Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00. | |
| Modificada | Media (4.3) | 1.2% | — | Hitachi WEB Page GeneratorHitachi WEB Page Generator Enterprise | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Media (5) | 1.4% | — | Hitachi WEB Page GeneratorAIHitachi WEB Page Generator EnterpriseAI | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in the error handler in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier, when using the default error template and debug mode is set to ON, allows remote attackers to determine internal directory structures via unknown attack vectors. | |
| Modificada | Alta (7.8) | 1.8% | — | Hitachi WEB Page GeneratorAIHitachi WEB Page Generator EnterpriseAI | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in Hitachi Web Page Generator and Web Page Generator Enterprise 4.01 and earlier allows remote attackers to cause a denial of service via unknown attack vectors when a web site is "improperly accessed." |