Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
535 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Phpscripte24 WEB Social Network Freunde Community | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Community CMS | 22/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event action to calendar.php, reachable through index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Systemsoftware Community Black Forum | 9/4/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter. | |
| Modificada | Media (5) | 15% | 💥 Exploit | Corejoomla COM Communitypolls | 23/3/2010 | 16/6/2026 | Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for Core Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Media-products Bild Flirt Community | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Bild Flirt Community 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Perlunity Phpunity.newsmanager | 2/3/2010 | 16/6/2026 | Directory traversal vulnerability in misc/tell_a_friend/tell.php in phpunity.newsmanager allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Invisioncommunity Invision Power Board | 18/11/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) search_term parameter to admin/applications/core/modules_public/search/search.php and (2) aid parameter to… | |
| Modificada | Media (4.3) | 0.85% | — | Xzeroscripts Xzero Community Classifieds | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.85% | — | Xzeroscripts Xzero Community Classifieds | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Xzeroscripts Xzero Community Classifieds | 20/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter. | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | 2daybiz Business Community Script | 16/5/2009 | 16/6/2026 | admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | 2daybiz Business Community Script | 16/5/2009 | 16/6/2026 | SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Community CMS | 3/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4) | 1.2% | — | Cisco Unity | 13/10/2008 | 16/6/2026 | Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8 uses weak permissions for the D:\CommServer\Reports directory, which allows remote authenticated users to obtain sensitive information by reading files in this directory. | |
| Modificada | Media (5) | 2.4% | — | Cisco Unity | 13/10/2008 | 16/6/2026 | Unspecified vulnerability in an unspecified Microsoft API, as used by Cisco Unity and possibly other products, allows remote attackers to cause a denial of service by sending crafted packets to dynamic UDP ports, related to a "processing error." | |
| Modificada | Alta (7.1) | 1.8% | — | Cisco Unity | 13/10/2008 | 16/6/2026 | Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to cause a denial of service (session exhaustion) via a large number of connections. | |
| Modificada | Baja (3.5) | 1.0% | — | Cisco Unity | 13/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before 4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows remote authenticated administrators to inject arbitrary web script or HTML by entering it in the database (aka data store). | |
| Modificada | Media (5.8) | 1.7% | — | Cisco Unity | 8/10/2008 | 16/6/2026 | Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM ComprofilerJoomlapolis Community BuilderMambo COM Comprofiler | 6/5/2008 | 16/6/2026 | SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php. | |
| Modificada | Media (6.5) | 1.3% | — | Mysql Community Server | 18/2/2008 | 16/6/2026 | MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements. | |
| Modificada | Media (4.3) | 0.84% | — | Sift Unity | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.cgi in Sift Unity allows remote attackers to inject arbitrary web script or HTML via the qt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.4) | 7.0% | 💥 Exploit | Xzero Scripts Xzero Community Classifieds | 28/12/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagename parameter in a page view action. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Xzero Scripts Xzero Community Classifieds | 28/12/2007 | 16/6/2026 | SQL injection vulnerability in post.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatid parameter to index.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Xzero Scripts Xzero Community Classifieds | 28/12/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter. | |
| Modificada | Alta (7.1) | 14% | — | Mysql ServerMysql Community ServerMysql Enterprise Server | 10/12/2007 | 16/6/2026 | MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and… |