Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

480 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Spirate Small Pirate22/7/201016/6/2026
Cross-site scripting (XSS) vulnerability in Small Pirate (SPirate) 2.1 allows remote attackers to inject arbitrary web script or HTML via an onmouseover action in an img BBCode tag within a url BBCode tag.
ModificadaAlta (7.5)1.8%💥 ExploitSpirate Small Pirate22/7/201016/6/2026
Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to the default URI in an rss .xml action, or the id parameter to (2) pag1.php, (3) pag1-guest.php, (4) rss-comment_post.php (aka rss-coment_post.php), or (5)…
ModificadaAlta (7.5)1.2%💥 ExploitThefactory COM Mediamall29/4/201016/6/2026
SQL injection vulnerability in the Media Mall Factory (com_mediamall) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php.
ModificadaAlta (10)1.2%—Chris Buccella Small Footprint CIM Broker14/9/200916/6/2026
Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors.
ModificadaAlta (7.5)1.0%💥 ExploitVirtuenetz Virtue Shopping Mall9/6/200916/6/2026
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (6.5)2.1%💥 ExploitStephane Rajalu Malleo28/4/200916/6/2026
Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPrezmo Small Shoutbox26/2/200916/6/2026
SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
ModificadaAlta (7.5)2.9%💥 ExploitPreprojects PRE Shopping Mall20/2/200916/6/2026
Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".
ModificadaAlta (7.5)2.7%💥 ExploitPreproject PRE Multi-vendor Shopping Malls20/2/200916/6/2026
Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin".
ModificadaAlta (7.5)0.97%💥 ExploitPreproject PRE Multi-vendor Shopping Malls20/2/200916/6/2026
SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute arbitrary SQL commands via the (1) sid and (2) cid parameters.
ModificadaAlta (7.5)0.97%💥 ExploitSepcity Shopping Mall16/2/200916/6/2026
SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Shopping Mall8/5/200816/6/2026
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
ModificadaAlta (7.5)2.0%💥 ExploitSmall AXE Solutions Weblog25/1/200816/6/2026
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (6.8)32%💥 ExploitSoftpedia Small AXE Weblog22/1/200816/6/2026
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter.
ModificadaMedia (6.8)0.91%💥 ExploitSmallnuke9/1/200816/6/2026
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action.
ModificadaAlta (7.1)32%—Microsoft Home ServerMicrosoft Small Business ServerMicrosoft Windows 2000Microsoft Windows 2003 Server+28/1/200816/6/2026
The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."
ModificadaMedia (6.8)7.3%—Sophos Anti-virusSophos Scanning EngineSophos Small Business Suite28/8/200716/6/2026
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows…
ModificadaAlta (7.8)5.5%—Sophos Anti-virusSophos Scanning EngineSophos Small Business Suite28/8/200716/6/2026
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
ModificadaAlta (7.5)7.7%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access.
ModificadaMedia (4.3)1.9%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected.
ModificadaMedia (6.8)1.1%💥 ExploitBugmall Shopping Cart27/6/200716/6/2026
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected.
ModificadaAlta (7.5)1.3%💥 ExploitPRE Projects PRE Shopping Mall14/5/200716/6/2026
SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter.
ModificadaMedia (5)1.1%—Koan Software Mega Mall20/3/200716/6/2026
product_review.php in Koan Software Mega Mall allows remote attackers to obtain the installation path via a request with an empty value of the x[] parameter.
ModificadaAlta (7.5)1.3%💥 ExploitKoan Software Mega Mall20/3/200716/6/2026
Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php.
ModificadaMedia (5.8)2.0%—Okscripts Okmall13/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkMall 1.0 allow remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: this might be resultant from another vulnerability, since the XSS is reflected in an error message.
Orbitaley — Vulnerabilidades