Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Codewidgets Real Estate Listing Website Application Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Media (6.8) | 64% | 💥 Exploit | Ripe Website Manager | 3/7/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the level parameter to (1) admin/includes/author_panel_header.php or (2) admin/includes/admin_header.php. | |
| Modificada | Alta (7.8) | 1.4% | — | Ripe Website Manager | 3/7/2007 | 16/6/2026 | Ripe Website Manager 0.8.9 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Obie Website Mini WEB Shop | 9/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) to (1) sendmail.php or (2) order_form.php, different vectors than CVE-2006-6734. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Ripe Website Manager | 24/4/2007 | 16/6/2026 | SQL injection vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to execute arbitrary SQL commands via the ripeformpost parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Ripe Website Manager | 24/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in contact/index.php in Ripe Website Manager 0.8.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a leading "<"<" in the ripeformpost parameter. | |
| Modificada | Alta (7.5) | 8.4% | 💥 Exploit | Grafx Software Company Website Builder | 2/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than… | |
| Modificada | Alta (7.5) | 1.1% | — | Advanced Website Creator | 30/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in the MySQL back-end in Advanced Website Creator (AWC) before 1.9.0 might allow remote attackers to execute arbitrary SQL commands via unspecified parameters, related to use of mysql_escape_string instead of mysql_real_escape_string. | |
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | Grafx Company Website Builder PRO | 20/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter. | |
| Modificada | Media (6.8) | 1.4% | — | Website Baker | 26/1/2007 | 16/6/2026 | SQL injection vulnerability in the is_remembered function in class.login.php in Website Baker 2.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the REMEMBER_KEY cookie parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 3.8% | 💥 Exploit | Neon Labs Website | 25/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/nl/nl.php in Neon Labs Website (nlws) 3.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the g_strRootDir parameter. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Scriptaty Magic Photo Storage Website | 12/1/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in magic photo storage website allow remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter to (1) admin_password.php, (2) add_welcome_text.php, (3) admin_email.php, (4) add_templates.php, (5) admin_paypal_email.php, (6)… | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Scriptaty Magic Photo Storage Website | 11/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote attackers to execute arbitrary PHP code via a URL in the _config[site_path] parameter. | |
| Modificada | Alta (10) | 1.9% | 💥 Exploit | Website Designs FOR Less Click N Print Coupons | 31/12/2006 | 16/6/2026 | SQL injection vulnerability in coupon_detail.asp in Website Designs For Less Click N' Print Coupons 2005.01 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter. | |
| Modificada | Media (5) | 1.7% | — | Obie Website Mini WEB Shop | 26/12/2006 | 16/6/2026 | modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to obtain sensitive information via a request with an arbitrary catname parameter but no itemsdb parameter, which reveals the path in an error message. NOTE: CVE analysis suggests that this error might be resultant… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Obie Website Mini WEB Shop | 26/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules/viewcategory.php in Minh Nguyen Duong Obie Website Mini Web Shop 2.1.c allows remote attackers to inject arbitrary web script or HTML via the catname parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Jelle DE VOS Bandwebsite | 23/12/2006 | 16/6/2026 | Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct request to admin.php with the Login parameter set to 1. | |
| Modificada | Media (6.8) | 1.0% | 💥 Exploit | Recipes Complete Website | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to execute arbitrary SQL commands via the (1) recipeid parameter to recipe.php or the (2) categoryid parameter to list.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Wallpaper Complete Website | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Wallpaper Website (Wallpaper Complete Website) 1.0.09 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameter to (a) process.php, or the (3) wallpaperid parameter to (b) dlwallpaper.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Wallpaper Complete Website | 1/12/2006 | 16/6/2026 | SQL injection vulnerability in wallpaper.php in Wallpaper Website (Wallpaper Complete Website) 1.0.09 allows remote attackers to execute arbitrary SQL commands via the wallpaperid parameter. | |
| Modificada | Media (6.8) | 1.4% | — | Website Designs FOR Less Inventory Manager | 17/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inventory/display/display_results.asp in Website Designs For Less Inventory Manager allows remote attackers to inject arbitrary web script or HTML via the category parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Website Designs FOR Less Inventory Manager | 17/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in inventory/display/imager.asp in Website Designs for Less Inventory Manager allow remote attackers to execute arbitrary SQL commands via the (1) pictable, (2) picfield, or (3) where parameter. | |
| Modificada | Media (5.1) | 3.4% | 💥 Exploit | SWS Simple Website Software | 1/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter. | |
| Modificada | Media (5.1) | 2.3% | — | Asbru Software Asbru WEB Content ManagementAsbru Software Asbru Website Manager | 12/10/2006 | 16/6/2026 | The spell checking component of (1) Asbru Web Content Management before 6.1.22, (2) Asbru Web Content Editor before 6.0.22, and (3) Asbru Website Manager before 6.0.22 allows remote attackers to execute arbitrary commands via an unspecified parameter that is not sanitized before Aspell is invoked. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Phpwebsite | 11/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php,… |