Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.5%💥 ExploitAlexandre Amaral Xoops Celepar15/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to cadastro_usuario.php.
ModificadaMedia (4.3)1.5%💥 ExploitAlexandre Amaral Xoops Celepar15/3/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to inject arbitrary web script or HTML via (1) the cod_categoria parameter to categoria.php, (2) the opcao parameter to index.php, and the PATH_INFO to (3) categoria.php and (4) index.php.
ModificadaAlta (7.5)1.7%💥 ExploitAlexandre Amaral Xoops Celepar15/3/201016/6/2026
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.
ModificadaBaja (3.5)2.8%💥 ExploitAlexander Hass Sections Module28/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal allows remote authenticated users with "administer sections" privileges to inject arbitrary web script or HTML via a section name (aka the Name field).
ModificadaMedia (6.5)2.0%💥 ExploitAlexander Palmo Simple PHP Blog24/12/200916/6/2026
Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the blog_language1 parameter.
ModificadaMedia (6)0.82%💥 ExploitRicardo Alexandre DE Oliveira Staudt Yogurt12/6/200916/6/2026
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authenticated users to execute arbitrary SQL commands via the original parameter.
ModificadaMedia (4.3)1.5%💥 ExploitRicardo Alexandre DE Oliveira Staudt Yogurt12/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaMedia (5)1.2%💥 ExploitVlad Alexa Mancini Phpfootball23/2/200916/6/2026
filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Accounts value for the dbtable parameter, in conjunction with a Password value for the dbfield parameter. NOTE: this has been reported as a SQL injection vulnerability by some sources, but the provenance…
ModificadaMedia (4.3)1.5%💥 ExploitVlad Alexa Mancini Phpfootball23/2/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web script or HTML via (1) the user parameter to login.php or (2) the dbfield parameter to filter.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (7.5)0.95%💥 ExploitVlad Alexa Mancini Phpfootball23/2/200916/6/2026
SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.3%—Alexander Palmo Simple PHP Blog24/9/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog) before 0.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via certain user_colors array parameters to certain user_style.php files under themes/, as demonstrated by the…
ModificadaAlta (7.5)3.0%—Alexander Palmo Simple PHP Blog24/9/200716/6/2026
Incomplete blacklist vulnerability in upload_img_cgi.php in Simple PHP Blog before 0.5.1 allows remote attackers to upload dangerous files and execute arbitrary code, as demonstrated by a filename ending in .php. or a .htaccess file, a different vector than CVE-2005-2733. NOTE: the vulnerability was also present in a…
ModificadaMedia (6.8)3.2%—Alexander V. Lukyanov Lftp27/4/200716/6/2026
mirror --script in lftp before 3.5.9 does not properly quote shell metacharacters, which might allow remote user-assisted attackers to execute shell commands via a malicious script. NOTE: it is not clear whether this issue crosses security boundaries, since the script already supports commands such as "get" which…
ModificadaMedia (5)3.1%💥 ExploitVlad Alexa Mancini Phpfootball31/1/200716/6/2026
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database contents) via a % (percent) character in the dbfieldv parameter.
ModificadaAlta (7.5)3.6%💥 ExploitJason Alexander Phnntp14/8/200616/6/2026
PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.
ModificadaAlta (7.5)9.7%💥 ExploitAlexander Palmo Simple PHP Blog15/3/200616/6/2026
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache…
ModificadaMedia (4.3)2.2%💥 ExploitAlexander Palmo Simple PHP Blog3/11/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4)…
ModificadaMedia (5)5.6%💥 ExploitAlexander Palmo Simple PHP Blog2/9/200516/6/2026
comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
ModificadaAlta (7.5)51%💥 ExploitAlexander Palmo Simple PHP Blog30/8/200516/6/2026
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
ModificadaBaja (2.6)1.4%—Alexander Clauss Icab13/7/200516/6/2026
iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
ModificadaMedia (5)4.1%💥 ExploitAlexander Palmo Simple PHP Blog11/7/200516/6/2026
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
ModificadaMedia (5)1.7%—Alexander Palmo Simple PHP Blog2/5/200516/6/2026
Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.
ModificadaMedia (5)1.3%—Alexander Palmo Simple PHP Blog2/5/200516/6/2026
Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.
ModificadaMedia (4.6)0.44%—Alexander Siegel Golddig2/5/200516/6/2026
Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.
ModificadaMedia (4.3)1.7%💥 ExploitAlexander Palmo Simple PHP Blog2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.