Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.96%💥 ExploitDesign-cars COM Productbook23/3/201016/6/2026
SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)2.7%💥 ExploitCarsten Wulff Simplephpweb10/9/200916/6/2026
admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)0.95%💥 ExploitJaredeckersley Mycars9/6/200916/6/2026
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authuserid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitRfaah Cars-vehicles Script22/9/200816/6/2026
SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.
ModificadaAlta (7.5)0.99%💥 ExploitCarscripts Classifieds25/6/200816/6/2026
SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaAlta (9.3)5.7%—Carsten Haitzler Imlib22/6/200816/6/2026
Multiple stack-based buffer overflows in Imlib 2 (aka imlib2) 1.4.0 allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) a PNM image with a crafted header, related to the load function in src/modules/loaders/loader_pnm.c; or (2) a crafted XPM image,…
ModificadaAlta (7.5)1.1%💥 ExploitEnthrallweb Ecars28/12/200616/6/2026
SQL injection vulnerability in Types.asp in Enthrallweb eCars 1.0 allows remote attackers to execute arbitrary SQL commands via the Type_id parameter.
ModificadaMedia (6.8)1.1%—Carsen Klock Textsend21/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Carsen Klock TextSend 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) error or (2) success parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitCars Portal7/12/200516/6/2026
SQL injection vulnerability in index.php in Cars Portal 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) page and (2) car parameters.
ModificadaMedia (5)1.7%—Ratbag Dirt Track RacingRatbag Dirt Track Racing AustraliaRatbag Dirt Track Racing Sprint CarsRatbag Leadfoot+123/11/200416/6/2026
Ratbag game engine, as used in products such as Dirt Track Racing, Leadfoot, and World of Outlaws Spring Cars, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet that specifies the length of data to read and then sends a second TCP packet that contains less data than specified,…
Orbitaley — Vulnerabilidades