Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.2% | 💥 Exploit | Dragonbyte-tech Vbshout | 11/1/2018 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action. | |
| Modificada | Media (4.3) | 1.9% | — | Webshophun Webshop HUN | 9/3/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Webshop hun 1.062S allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) center, (3) lap, (4) termid, or (5) nyelv_id parameter to index.php. | |
| Modificada | Alta (7.5) | 3.1% | — | Webshophun Webshop HUN | 9/3/2015 | 17/6/2026 | Directory traversal vulnerability in Webshop hun 1.062S allows remote attackers to have unspecified impact via directory traversal sequences in the mappa parameter to index.php. | |
| Modificada | Alta (7.5) | 2.2% | — | Webshophun Webshop HUN | 9/3/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in Webshop hun 1.062S allow remote attackers to execute arbitrary SQL commands via the (1) termid or (2) nyelv_id parameter to index.php. | |
| Modificada | Media (6.8) | 3.6% | 💥 Exploit | Bestwebsharing Groovy Media Player | 16/4/2013 | 16/6/2026 | Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file. | |
| Modificada | Alta (7.5) | 2.1% | — | Digineo Thumbshooter | 9/4/2013 | 16/6/2026 | lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Media (5.4) | 0.57% | — | IBM Webshere Cast Iron Cloud Integration | 22/2/2013 | 16/6/2026 | Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Burnsy Jbshop Plugin | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in jbshop.php in the jbShop plugin for e107 7 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Freewebshop | 31/8/2012 | 16/6/2026 | Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeWebshop 2.2.9 R2 and earlier allows remote attackers to inject arbitrary PHP code into data.php via the selected document, as demonstrated by a call to ajax_file_cut.php and then to ajax_save_name.php. | |
| Modificada | Media (6.8) | 3.0% | — | Bestwebsharing Groovy Media Player | 12/7/2010 | 16/6/2026 | Stack-based buffer overflow in Groovy Media Player 1.1.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file. | |
| Modificada | Alta (7.2) | 0.75% | 💥 Exploit | Kingsoft Webshield | 24/5/2010 | 16/6/2026 | KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device. | |
| Modificada | Media (5) | 1.5% | — | Phpspot PHP & CSS BBSPhpspot PHP BBSPhpspot PHP BBS CEPhpspot PHP Image Capture BBS+2 | 22/9/2009 | 16/6/2026 | Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Phpspot PHP & CSS BBSPhpspot PHP BBSPhpspot PHP BBS CEPhpspot PHP Image Capture BBS+2 | 22/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to cookies. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Linuxwebshop PHP User Base | 17/9/2009 | 16/6/2026 | Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and execute arbitrary local files via the template parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Freewebshop | 7/7/2009 | 16/6/2026 | Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_file parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Webbdomain Webshop Online | 6/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Webbdomain Webshop | 6/4/2009 | 16/6/2026 | SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Sadi Samami Multi Languages Webshop Online | 25/2/2009 | 16/6/2026 | SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Sadi Samami Multi Languages Webshop Online | 25/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in detail.php in Multi Languages WebShop Online 1.02 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Linuxwebshop PHP Help Agent | 30/7/2008 | 16/6/2026 | Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname… | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | HIS Webshop | 28/3/2008 | 16/6/2026 | Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter. | |
| Modificada | Alta (10) | 2.2% | — | Freewebshop | 24/3/2008 | 16/6/2026 | Unspecified vulnerability in customer.php in FreeWebshop.org 2.2.5, 2.2.6 and 2.2.7WIP1/2 allows remote attackers to gain administrator privileges via unknown vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Freewebshop | 20/12/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the prod parameter in a details action, (2) the cat parameter in a browse list action, or (3) the group parameter in a categories action. NOTE: it was later reported that MOG - Web… | |
| Modificada | Alta (7.5) | 2.0% | — | Freewebshop | 26/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/login.php in FreeWebShop 2.2.3 and 2.2.4 before 20070123 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Freewebshop | 19/1/2007 | 16/6/2026 | index.php in FreeWebshop 2.2.2 and earlier allows remote attackers to obtain sensitive information via an invalid action parameter in an info operation, which discloses the path in an error message. |