Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Etoshop Dynamic BIZ Website Builder Quickweb | 21/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp. | |
| Modificada | Media (5) | 1.1% | — | Oscommerce Online MerchantPaypal Website Payments Standard Module | 19/9/2012 | 16/6/2026 | The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Kajianwebsite CMS Balitbang | 23/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Kajian Website CMS Balitbang 3.x allow remote attackers to execute arbitrary SQL commands via the hal parameter to (1) the data module in alumni.php; or the (2) lih_buku, (3) artikel, (4) album, or (5) berita module in index.php. | |
| Modificada | Media (5.8) | 10% | 💥 Exploit | Websitepanel | 17/7/2012 | 16/6/2026 | Open redirect vulnerability in the login page in WebsitePanel before 1.2.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in ReturnUrl to Default.aspx. | |
| Modificada | Media (4.3) | 0.84% | — | Phpwebsite | 8/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpWebSite before 1.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Micronetsoft Rental Property Website | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Micronetsoft RV Dealer Website | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbitrary SQL commands via the vehicletypeID parameter. | |
| Modificada | Media (5) | 1.2% | — | Websitebaker2 Website Baker | 24/9/2011 | 16/6/2026 | Website Baker 2.8.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/media/parameters.php and certain other files. NOTE: this might overlap CVE-2005-2436. | |
| Modificada | Media (5) | 1.3% | — | Escortwebsitedesign Escort-agency-cms | 23/9/2011 | 16/6/2026 | Escort Agency CMS (aka escort-agency-cms) allows remote attackers to obtain sensitive information via crafted array parameters in a request to a .php file, which reveals the installation path in an error message, as demonstrated by makethumb.php and certain other files. | |
| Modificada | Media (4.3) | 0.84% | — | Lepton-cms LeptonWebsitebaker2 Websitebaker | 2/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unknown vectors, a different vulnerability than CVE-2006-2307. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Micronetsoft RV Dealer Website | 1/12/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp. | |
| Modificada | Alta (7.5) | 1.3% | — | Netartmedia Websiteadmin | 29/9/2010 | 16/6/2026 | Directory traversal vulnerability in ADMIN/login.php in NetArtMEDIA WebSiteAdmin allows remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the lng parameter. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Websitesrus Accessories ME PHP Affiliate Script | 25/8/2010 | 16/6/2026 | SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL commands via the Go parameter. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Websitesrus Accessories ME PHP Affiliate Script | 25/8/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Keywords parameter to search.php and (2) SearchIndex parameter to browse.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Brotherscripts Recipe Website | 8/7/2010 | 16/6/2026 | SQL injection vulnerability in recipedetail.php in BrotherScripts Recipe Website allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Easysitenetwork Jokes Complete Website | 25/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Jokes Complete Website allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to joke.php and the (2) searchingred parameter to results.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Resalecode PHP Shopping Cart Selling Website Script | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | Resalecode PHP Shopping Cart Selling Website Script | 10/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Multi-website Multi Website | 10/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Multi-website Multi Website | 10/9/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action. | |
| Modificada | Alta (7.5) | 2.1% | — | Ezonescripts Dating Website Script | 19/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in eZoneScripts Dating Website script allows remote attackers to execute arbitrary code via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Easysitenetwork Jokes Complete Website | 30/7/2009 | 16/6/2026 | SQL injection vulnerability in joke.php in EasySiteNetwork Free Jokes Website allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Resalecode Hutscripts PHP Website Script | 24/7/2009 | 16/6/2026 | SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Resalecode Hutscripts PHP Website Script | 24/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP Website Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Kimwebsites KIM Websites | 20/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. |