Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
480 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Spirate Small Pirate | 22/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Small Pirate (SPirate) 2.1 allows remote attackers to inject arbitrary web script or HTML via an onmouseover action in an img BBCode tag within a url BBCode tag. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Spirate Small Pirate | 22/7/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to the default URI in an rss .xml action, or the id parameter to (2) pag1.php, (3) pag1-guest.php, (4) rss-comment_post.php (aka rss-coment_post.php), or (5)… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Thefactory COM Mediamall | 29/4/2010 | 16/6/2026 | SQL injection vulnerability in the Media Mall Factory (com_mediamall) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php. | |
| Modificada | Alta (10) | 1.2% | — | Chris Buccella Small Footprint CIM Broker | 14/9/2009 | 16/6/2026 | Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Virtuenetz Virtue Shopping Mall | 9/6/2009 | 16/6/2026 | SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (6.5) | 2.1% | 💥 Exploit | Stephane Rajalu Malleo | 28/4/2009 | 16/6/2026 | Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Prezmo Small Shoutbox | 26/2/2009 | 16/6/2026 | SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Preprojects PRE Shopping Mall | 20/2/2009 | 16/6/2026 | Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin". | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Preproject PRE Multi-vendor Shopping Malls | 20/2/2009 | 16/6/2026 | Pre Multi-Vendor Shopping Malls allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin". | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preproject PRE Multi-vendor Shopping Malls | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in buyer_detail.php in Pre Multi-Vendor Shopping Malls allows remote attackers to execute arbitrary SQL commands via the (1) sid and (2) cid parameters. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Sepcity Shopping Mall | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Shopping Mall | 8/5/2008 | 16/6/2026 | SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the search parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Small AXE Solutions Weblog | 25/1/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a different vector than CVE-2008-0376. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (6.8) | 32% | 💥 Exploit | Softpedia Small AXE Weblog | 22/1/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Smallnuke | 9/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via (1) the user_email parameter and possibly (2) username parameter in a Members action. | |
| Modificada | Alta (7.1) | 32% | — | Microsoft Home ServerMicrosoft Small Business ServerMicrosoft Windows 2000Microsoft Windows 2003 Server+2 | 8/1/2008 | 16/6/2026 | The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability." | |
| Modificada | Media (6.8) | 7.3% | — | Sophos Anti-virusSophos Scanning EngineSophos Small Business Suite | 28/8/2007 | 16/6/2026 | Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows… | |
| Modificada | Alta (7.8) | 5.5% | — | Sophos Anti-virusSophos Scanning EngineSophos Small Business Suite | 28/8/2007 | 16/6/2026 | Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb"). | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers to obtain login access. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in BugMall Shopping Cart 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the msgs parameter. NOTE: 4.0.2 and other versions might also be affected. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Bugmall Shopping Cart | 27/6/2007 | 16/6/2026 | SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the "basic search box." NOTE: 4.0.2 and other versions might also be affected. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | PRE Projects PRE Shopping Mall | 14/5/2007 | 16/6/2026 | SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter. | |
| Modificada | Media (5) | 1.1% | — | Koan Software Mega Mall | 20/3/2007 | 16/6/2026 | product_review.php in Koan Software Mega Mall allows remote attackers to obtain the installation path via a request with an empty value of the x[] parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Koan Software Mega Mall | 20/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Koan Software Mega Mall allow remote attackers to execute arbitrary SQL commands via the (1) t, (2) productId, (3) sk, (4) x, or (5) so parameter to (a) product_review.php; or the (6) orderNo parameter to (b) order-track.php. | |
| Modificada | Media (5.8) | 2.0% | — | Okscripts Okmall | 13/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkMall 1.0 allow remote attackers to inject arbitrary web script or HTML via the page parameter. NOTE: this might be resultant from another vulnerability, since the XSS is reflected in an error message. |