Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%💥 ExploitHpecs Shopping Cart17/11/200616/6/2026
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields in the (a) login screen, and (3) searchstring parameter in (b) insearch_list.asp.
ModificadaAlta (7.5)2.2%💥 ExploitPhpeasydata PRO4/11/200616/6/2026
SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaAlta (7.5)3.4%💥 ExploitPhpecard31/8/200616/6/2026
PHP remote file inclusion vulnerability in functions.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
ModificadaAlta (7.5)1.3%—Phpecard31/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaAlta (7.5)2.5%💥 ExploitJevontech Phpenpals4/1/200616/6/2026
SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via the personalID parameter. NOTE: it was later reported that 1.1 and earlier are affected.
ModificadaAlta (7.5)1.4%—Butterfat Phpesp1/11/200516/6/2026
SQL injection vulnerability in phpESP 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (4.3)1.3%—Butterfat Phpesp1/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in phpESP 1.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaAlta (7.5)2.6%—Wesmo Phpeventcalendar31/12/200216/6/2026
Unknown vulnerability in WesMo phpEventCalendar 1.1 allows remote attackers to execute arbitrary commands via unknown attack vectors.
ModificadaMedia (6.4)3.2%💥 ExploitHPE Compaq Wl310 FirmwareProxim Orinoco Rg-1000 FirmwareProxim Orinoco Rg-1100 Firmware12/8/200216/6/2026
Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.
Orbitaley — Vulnerabilidades