Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Alibabaclone B2B Gold Script | 6/5/2010 | 16/6/2026 | SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Alibabaclone Ec21 Clone | 6/5/2010 | 16/6/2026 | SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Alibabaclone Alibaba Clone Platinum | 6/5/2010 | 16/6/2026 | SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Alibabaclone Alibaba Clone | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | WEB Development House Alibaba Clone | 13/7/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is… | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Alibaba Alipay Activex Control | 7/2/2007 | 16/6/2026 | The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Computer Software Manufaktur Alibaba | 18/7/2000 | 16/6/2026 | Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request. | |
| Modificada | Media (5) | 1.1% | — | Computer Software Manufaktur Alibaba | 31/12/1999 | 16/6/2026 | genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext. | |
| Modificada | Baja (3.6) | 2.8% | 💥 Exploit | Computer Software Manufaktur Alibaba | 3/11/1999 | 16/6/2026 | Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL. | |
| Modificada | Media (5) | 1.4% | — | Computer Software Manufaktur Alibaba | 12/5/1999 | 16/6/2026 | Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack. |