Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.55% | — | Website Seller Script Project Website Seller Script | 28/8/2018 | 17/6/2026 | PHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name. | |
| Modificada | Alta (8.8) | 0.51% | — | Chartered Accountant \ Auditor Website Project | 10/8/2018 | 17/6/2026 | PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | SSH Companywebsite Project SSH Companywebsite | 20/7/2018 | 17/6/2026 | An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type. | |
| Modificada | Crítica (9.8) | 1.1% | — | SSH Companywebsite Project SSH Companywebsite | 20/7/2018 | 17/6/2026 | An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Chartered Accountant \ Auditor Website Project | 9/7/2018 | 17/6/2026 | PHP Scripts Mall Auditor Website 2.0.1 has XSS via the lastname or firstname parameter. | |
| Modificada | Alta (8.8) | 0.63% | — | Website Seller Script Project Website Seller Script | 26/5/2018 | 17/6/2026 | PHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS. | |
| Modificada | Media (5.4) | 0.51% | — | Website Broker Script Project Website Broker Script | 12/4/2018 | 17/6/2026 | PHP Scripts Mall Website Broker Script 3.0.6 has XSS via the Last Name field on the My Profile page. | |
| Modificada | Alta (8.8) | 1.0% | — | Website Seller Script Project Website Seller Script | 12/4/2018 | 17/6/2026 | PHP Scripts Mall Website Seller Script 2.0.3 uses the client side to enforce validation of an e-mail address, which allows remote attackers to modify a registered e-mail address by removing the validation code. | |
| Modificada | Media (6.1) | 0.65% | — | Website Seller Script Project Website Seller Script | 12/4/2018 | 17/6/2026 | Reflected XSS exists in PHP Scripts Mall Website Seller Script 2.0.3 via the Listings Search feature. | |
| Modificada | Crítica (9.8) | 1.7% | — | News Website Script Project News Website Script | 13/2/2018 | 17/6/2026 | PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term. | |
| Modificada | Media (6.1) | 0.63% | — | Websitebaker | 10/1/2018 | 17/6/2026 | Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Freelance Website Script Project Freelance Website Script | 13/12/2017 | 17/6/2026 | Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | CMS Auditor Website Project CMS Auditor Website | 13/12/2017 | 17/6/2026 | CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Website Auction Marketplace Project Website Auction Marketplace | 13/12/2017 | 17/6/2026 | Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Website Broker Script Project Website Broker Script | 31/10/2017 | 17/6/2026 | Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php. | |
| Modificada | Media (6.1) | 0.99% | — | Smartwebsites Smartcms | 28/8/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2. | |
| Modificada | Crítica (9.8) | 1.4% | — | Websitebaker | 21/6/2017 | 17/6/2026 | install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or database_password parameter. | |
| Modificada | Media (6.1) | 0.63% | — | Websitebaker | 2/6/2017 | 17/6/2026 | WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Websitebaker | 2/6/2017 | 17/6/2026 | WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php. | |
| Modificada | Alta (8.8) | 1.6% | — | Information-technology Promotion Agency Introduction TO Safe Website Operation | 28/4/2017 | 17/6/2026 | Security guide for website operators allows remote attackers to execute arbitrary OS commands via specially crafted saved data. | |
| Modificada | Crítica (9.8) | 2.9% | 💥 PoC | Websitebaker | 3/4/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter. | |
| Modificada | Media (4.3) | 2.0% | — | Websitebaker | 21/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Mywebsiteadvisor Simple Security | 15/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) datefilter parameter in the access_log page to wp-admin/users.php or (2) simple_security_ip_blacklist[] parameter… | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Websitebaker | 3/12/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to wb/admin/admintools/tool.php or (2) section_id parameter to edit_module_files.php, (3) news/add_post.php, (4) news/modify_group.php, (5)… | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Websitebaker | 3/12/2014 | 17/6/2026 | SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via the page_id parameter. |