Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)4.2%💥 ExploitDragonbyte-tech Vbshout11/1/201816/6/2026
Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.
ModificadaMedia (4.3)1.9%—Webshophun Webshop HUN9/3/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Webshop hun 1.062S allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) center, (3) lap, (4) termid, or (5) nyelv_id parameter to index.php.
ModificadaAlta (7.5)3.1%—Webshophun Webshop HUN9/3/201517/6/2026
Directory traversal vulnerability in Webshop hun 1.062S allows remote attackers to have unspecified impact via directory traversal sequences in the mappa parameter to index.php.
ModificadaAlta (7.5)2.2%—Webshophun Webshop HUN9/3/201517/6/2026
Multiple SQL injection vulnerabilities in Webshop hun 1.062S allow remote attackers to execute arbitrary SQL commands via the (1) termid or (2) nyelv_id parameter to index.php.
ModificadaMedia (6.8)3.6%💥 ExploitBestwebsharing Groovy Media Player16/4/201316/6/2026
Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file.
ModificadaAlta (7.5)2.1%—Digineo Thumbshooter9/4/201316/6/2026
lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
ModificadaMedia (5.4)0.57%—IBM Webshere Cast Iron Cloud Integration22/2/201316/6/2026
Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.
ModificadaMedia (4.3)1.3%💥 ExploitBurnsy Jbshop Plugin20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter.
ModificadaMedia (5)2.3%💥 ExploitFreewebshop31/8/201216/6/2026
Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and earlier allows remote attackers to inject arbitrary PHP code into data.php via the selected document, as demonstrated by a call to ajax_file_cut.php and then to ajax_save_name.php.
ModificadaMedia (6.8)3.0%—Bestwebsharing Groovy Media Player12/7/201016/6/2026
Stack-based buffer overflow in Groovy Media Player 1.1.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.
ModificadaAlta (7.2)0.75%💥 ExploitKingsoft Webshield24/5/201016/6/2026
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device.
ModificadaMedia (5)1.5%—Phpspot PHP & CSS BBSPhpspot PHP BBSPhpspot PHP BBS CEPhpspot PHP Image Capture BBS+222/9/200916/6/2026
Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)1.0%—Phpspot PHP & CSS BBSPhpspot PHP BBSPhpspot PHP BBS CEPhpspot PHP Image Capture BBS+222/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to cookies.
ModificadaAlta (7.5)6.3%💥 ExploitLinuxwebshop PHP User Base17/9/200916/6/2026
Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and execute arbitrary local files via the template parameter.
ModificadaMedia (6.8)2.0%💥 ExploitFreewebshop7/7/200916/6/2026
Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file parameter.
ModificadaMedia (4.3)1.5%💥 ExploitWebbdomain Webshop Online6/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
ModificadaAlta (7.5)1.0%💥 ExploitWebbdomain Webshop6/4/200916/6/2026
SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaAlta (7.5)1.00%💥 ExploitSadi Samami Multi Languages Webshop Online25/2/200916/6/2026
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.5%💥 ExploitSadi Samami Multi Languages Webshop Online25/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter.
ModificadaMedia (6.8)2.0%💥 ExploitLinuxwebshop PHP Help Agent30/7/200816/6/2026
Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname…
ModificadaMedia (4.3)2.9%💥 ExploitHIS Webshop28/3/200816/6/2026
Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.
ModificadaAlta (10)2.2%—Freewebshop24/3/200816/6/2026
Unspecified vulnerability in customer.php in FreeWebshop.org 2.2.5, 2.2.6 and 2.2.7WIP1/2 allows remote attackers to gain administrator privileges via unknown vectors.
ModificadaAlta (7.5)1.2%💥 ExploitFreewebshop20/12/200716/6/2026
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter in a browse list action, or (3) the group parameter in a categories action. NOTE: it was later reported that MOG - Web…
ModificadaAlta (7.5)2.0%—Freewebshop26/1/200716/6/2026
PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.
ModificadaMedia (5)2.4%💥 ExploitFreewebshop19/1/200716/6/2026
index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path in an error message.
Orbitaley — Vulnerabilidades