Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Atomphotoblog | 28/7/2008 | 16/6/2026 | SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execute arbitrary SQL commands via the photoId parameter in a show action. | |
| Modificada | Alta (10) | 6.3% | 💥 Exploit | Neutrino-cms Atomic Edition | 11/7/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by manipulating data/sess.php in (1) usb and (2) del_pag actions. NOTE: this can be leveraged for code execution by performing an upload that bypasses the intended access… | |
| Modificada | Media (5) | 1.1% | — | Drupal Atom Module | 15/1/2008 | 16/6/2026 | The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow remote attackers to gain access to syndicated content. | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | Atomix Productions Atomixmp3 | 11/9/2007 | 16/6/2026 | Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in file and title fields in a .pls file, as demonstrated by the (1) File1 and (2) Title1 fields, different vectors than CVE-2006-6287 and CVE-2007-2487. | |
| Modificada | Media (4.3) | 1.4% | — | Atom Photoblog | 8/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in atomPhotoBlog.php in Atom Photoblog 1.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the tag parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Atom Photoblog | 8/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in atomPhotoBlog.php in Atom PhotoBlog 1.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Your Name, (2) Your Homepage, and (3) Your Comment fields, when using "Approve Comments." | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | Atomix Productions Atomixmp3 | 3/5/2007 | 16/6/2026 | Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than CVE-2006-6287. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Atomix Productions Atomixmp3 | 4/12/2006 | 16/6/2026 | Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pathname in an M3U file. | |
| Modificada | Media (5) | 1.6% | — | Atomic Photo Album | 3/8/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter. |