Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
409 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Hpecs Shopping Cart | 17/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Phpeasydata PRO | 4/11/2006 | 16/6/2026 | SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Phpecard | 31/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in functions.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpecard | 31/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Jevontech Phpenpals | 4/1/2006 | 16/6/2026 | SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected. | |
| Modificada | Alta (7.5) | 1.4% | — | Butterfat Phpesp | 1/11/2005 | 16/6/2026 | SQL injection vulnerability in phpESP 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Butterfat Phpesp | 1/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpESP 1.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Wesmo Phpeventcalendar | 31/12/2002 | 16/6/2026 | Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors. | |
| Modificada | Media (6.4) | 3.2% | 💥 Exploit | HPE Compaq Wl310 FirmwareProxim Orinoco Rg-1000 FirmwareProxim Orinoco Rg-1100 Firmware | 12/8/2002 | 16/6/2026 | Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string. |