Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

496 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.8%💥 ExploitEmetrix Extract Website27/2/200916/6/2026
Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
ModificadaAlta (7.5)0.96%💥 ExploitAppstate Phpwebsite25/2/200916/6/2026
SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.
ModificadaAlta (7.5)1.2%💥 ExploitEzonescripts Adult Banner Exchange Website10/2/200916/6/2026
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PHP Jobwebsite PRO27/1/200916/6/2026
SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.
ModificadaMedia (4.3)1.5%💥 ExploitPreprojects PHP Jobwebsite PRO27/1/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname parameter in a Submit action or (2) the UserName field.
ModificadaMedia (4.3)1.5%💥 ExploitPhpclanwebsite8/1/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter and other unspecified vectors.
ModificadaMedia (5.1)1.9%💥 ExploitPhpclanwebsite8/1/200916/6/2026
Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the (1) boxname parameter to theme/superchrome/box.php and the…
ModificadaMedia (6.8)0.91%💥 ExploitPhpclanwebsite8/1/200916/6/2026
Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) form_id parameter to pcw/processforms.php, (3) pcwlogin and (4) pcw_pass parameters…
ModificadaMedia (4.3)1.5%💥 ExploitMultimania Bandsite Portal SystemMultimania Bandwebsite5/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
ModificadaAlta (7.5)1.00%💥 ExploitMultimania Bandsite Portal SystemMultimania Bandwebsite5/12/200816/6/2026
SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitEasysitenetwork Jokes Complete Website19/11/200816/6/2026
SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitEasysitenetwork Cheats Complete Website19/11/200816/6/2026
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
ModificadaAlta (7.5)1.0%💥 ExploitEasysitenetwork Drinks Complete Website19/11/200816/6/2026
SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter.
ModificadaAlta (7.5)1.0%💥 ExploitEasysitenetwork Tips Complete Website19/11/200816/6/2026
SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL commands via the tipid parameter.
ModificadaAlta (7.5)1.0%💥 ExploitEasysitenetwork Riddles Website19/11/200816/6/2026
SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter.
ModificadaMedia (4.3)3.0%💥 ExploitMaxiscript Website Directory9/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action.
ModificadaAlta (7.5)1.0%💥 ExploitPreprojects PHP Jobwebsite PRO30/6/200816/6/2026
SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or (2) position parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.5%💥 ExploitEwebsite Eweather17/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in the eWebsite eWeather (Weather) module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the chart parameter to modules.php.
ModificadaBaja (3.6)0.43%—Website Meta Language11/2/200816/6/2026
Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_eperl/eperl_sys.c.
ModificadaBaja (3.6)0.43%—Website Meta Language11/2/200816/6/2026
wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file.
ModificadaMedia (6.8)0.91%💥 ExploitEasysitenetwork Recipe Website Script25/1/200816/6/2026
SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.
ModificadaMedia (4.3)1.7%💥 ExploitPhpwebsite4/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaAlta (7.5)0.99%💥 ExploitWallpaper Complete Website28/12/200716/6/2026
Multiple SQL injection vulnerabilities in Wallpaper Site 1.0.09 allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter to category.php or (2) the groupid parameter to editadgroup.php.
ModificadaBaja (3.5)1.1%—Ripe Website Manager25/8/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c)…
ModificadaMedia (6)1.7%💥 ExploitRipe Website Manager25/8/200716/6/2026
Multiple SQL injection vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via one or more of the following vectors: the (1) id parameter to (a) pages/delete_page.php, (b) navigation/delete_menu.php, and (c) navigation/delete_item.php in admin/;…