Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.8% | 💥 Exploit | Emetrix Extract Website | 27/2/2009 | 16/6/2026 | Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Appstate Phpwebsite | 25/2/2009 | 16/6/2026 | SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ezonescripts Adult Banner Exchange Website | 10/2/2009 | 16/6/2026 | SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PHP Jobwebsite PRO | 27/1/2009 | 16/6/2026 | SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Preprojects PHP Jobwebsite PRO | 27/1/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname parameter in a Submit action or (2) the UserName field. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpclanwebsite | 8/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter and other unspecified vectors. | |
| Modificada | Media (5.1) | 1.9% | 💥 Exploit | Phpclanwebsite | 8/1/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the (1) boxname parameter to theme/superchrome/box.php and the… | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Phpclanwebsite | 8/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) form_id parameter to pcw/processforms.php, (3) pcwlogin and (4) pcw_pass parameters… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Multimania Bandsite Portal SystemMultimania Bandwebsite | 5/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Multimania Bandsite Portal SystemMultimania Bandwebsite | 5/12/2008 | 16/6/2026 | SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Easysitenetwork Jokes Complete Website | 19/11/2008 | 16/6/2026 | SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Easysitenetwork Cheats Complete Website | 19/11/2008 | 16/6/2026 | SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Easysitenetwork Drinks Complete Website | 19/11/2008 | 16/6/2026 | SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Easysitenetwork Tips Complete Website | 19/11/2008 | 16/6/2026 | SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL commands via the tipid parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Easysitenetwork Riddles Website | 19/11/2008 | 16/6/2026 | SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter. | |
| Modificada | Media (4.3) | 3.0% | 💥 Exploit | Maxiscript Website Directory | 9/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Preprojects PHP Jobwebsite PRO | 30/6/2008 | 16/6/2026 | SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or (2) position parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Ewebsite Eweather | 17/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in the eWebsite eWeather (Weather) module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the chart parameter to modules.php. | |
| Modificada | Baja (3.6) | 0.43% | — | Website Meta Language | 11/2/2008 | 16/6/2026 | Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_eperl/eperl_sys.c. | |
| Modificada | Baja (3.6) | 0.43% | — | Website Meta Language | 11/2/2008 | 16/6/2026 | wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Easysitenetwork Recipe Website Script | 25/1/2008 | 16/6/2026 | SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Phpwebsite | 4/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Wallpaper Complete Website | 28/12/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php. | |
| Modificada | Baja (3.5) | 1.1% | — | Ripe Website Manager | 25/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c)… | |
| Modificada | Media (6) | 1.7% | 💥 Exploit | Ripe Website Manager | 25/8/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/;… |