Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.94% | 💥 Exploit | Php-fusion Members CV Module | 5/3/2009 | 16/6/2026 | SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Ocean12tech Membership Manager PRO | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Ocean12tech Membership Manager PRO | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter). | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ezonelink Multiple Membership Script | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in sitepage.php in Multiple Membership Script 2.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Activewebsoftwares Active Membership | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.3% | — | Ocean12 Technologies Membership Manager PRO | 18/11/2008 | 16/6/2026 | Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Develop IT Easy Membership System | 13/11/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters to customer_login.php and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained… | |
| Modificada | Media (4.3) | 0.87% | — | Xoops Xm-memberstats | 28/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability index.php in the XM-Memberstats (xmmemberstats) module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the sortby parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Xoops XM Memberstats | 28/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arbitrary SQL commands via the (1) letter or (2) sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Agtc Websolutions Php-agtc Membership System | 31/10/2007 | 16/6/2026 | adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts via a modified form, as demonstrated by an account with admin (userlevel 4) privileges. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Interactive-scripts.com PHP Membership Manager | 30/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remote attackers to inject arbitrary web script or HTML via the _p parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Ememberspro | 9/1/2007 | 16/6/2026 | EMembersPro 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for users.mdb. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | PHP AR Memberscript | 15/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter. | |
| Modificada | Alta (10) | 1.4% | — | David Walker Phpautomembersarea | 11/8/2006 | 16/6/2026 | Unspecified vulnerability in phpAutoMembersArea (phpAMA) before 3.2.4 has unknown impact and attack vectors, related to "a potential security exploit which is critical." | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | David Walker Phpautomembersarea | 10/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter. | |
| Modificada | Media (4.9) | 1.1% | — | Agtc Websolutions Php-agtc Membership System | 31/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter). | |
| Modificada | Alta (7.5) | 1.5% | 💥 Exploit | Blackorpheus Clanmemberskript | 20/4/2006 | 16/6/2026 | SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userID parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Xbrite Members | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in members.php in XBrite Members 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.3% | — | Manas Tungare Site Membership Script | 12/3/2006 | 16/6/2026 | SQL injection vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to execute arbitrary SQL commands via the Username parameter in login.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Manas Tungare Site Membership Script | 12/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in manas tungare Site Membership Script before 8 March, 2006 allows remote attackers to inject arbitrary web script or HTML via the Error parameter in (1) login.asp and (2) default.asp. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Pehepe Membership Management SystemPehepe Uyelik Sistemi | 7/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to inject arbitrary web script or HTML via the kuladi parameter ($kul_adi variable). | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Pehepe Membership Management System | 7/3/2006 | 16/6/2026 | PHP remote file include vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to include and execute arbitrary PHP code via a URL in the uye_klasor parameter, along with a misafir[] parameter that is set to UYE_SEVIYE. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Ocean12 Technologies Membership Manager PRO | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Ocean12 Technologies Membership Manager PRO | 6/4/2005 | 16/6/2026 | SQL injection vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to execute arbitrary SQL commands via the UserID parameter. |