Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 4.1% | — | Particlesoftware Intralaunch | 13/4/2009 | 16/6/2026 | Insecure method vulnerability in Particle Software IntraLaunch Application Launcher ActiveX control in IntraLaunch.ocx, as used in LDRA TBbrowse and possibly other products, allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Codeavalanche Articles | 12/1/2009 | 16/6/2026 | CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAArticles.mdb. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | MyarticlesRuncms Myarticles Module | 5/5/2008 | 16/6/2026 | SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a listarticles action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Xoops Articles Module | 21/6/2007 | 16/6/2026 | SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (10) | 6.4% | 💥 Exploit | Keith Reichley Dotwidget FOR Articles | 24/2/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in DotWidget For Articles (dotwidgeta) 0.2 allow remote attackers to execute arbitrary code via a URL in the (1) file_path parameter to (a) index.php, (b) showcatpicks.php, and (c) showarticle.php; and the (2) admin_header_file and (3) admin_footer_file parameters to… | |
| Modificada | Media (6.8) | 1.2% | — | Myarticles | 10/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the MyArticles module before 0.6 beta 1, for RunCMS, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) topics.php, (2) submit.php, and (3) class/calendar.class.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Techno Dreams Articles AND Papers Package | 19/9/2006 | 16/6/2026 | SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Okscripts Okarticles | 13/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Articlesone 99articles Directory | 22/3/2006 | 16/6/2026 | PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | DWC ArticlesAI | 23/10/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dwc_articles 1.6 and earlier allow remote attackers to execute arbitrary SQL statements. |