Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | — | Cms.brdconcept Cms-brd | 24/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the menuclick parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Divideconcept VHD WEB Pack | 6/2/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |
| Modificada | Media (6.8) | 3.5% | — | CJG Explorer PROVincent Blavet Phpconcept Library | 14/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, as used in CJG EXPLORER PRO 3.3 and earlier and probably other products, allows remote attackers to execute arbitrary PHP code via a URL in the g_pcltar_lib_dir parameter. NOTE: CVE disputes this… | |
| Modificada | Media (6.8) | 1.1% | — | Openconcept Back-end CMS | 18/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in htdocs/php.php in OpenConcept Back-End CMS 0.4.7 allows remote attackers to inject arbitrary web script or HTML via the page[] parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Openconcept Back-end CMS | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End CMS 0.4.7 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter to (1) click.php or (2) pollcollector.php in htdocs/; or (3) index.php, (4) articlepages.php, (5) articles.php, (6) articleform.php, (7)… | |
| Modificada | Alta (7.5) | 1.3% | — | Bare Concept Media Pheap CMS | 7/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in settings.php in Pheap 1.2, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The lib/config.php vector is… | |
| Modificada | Alta (7.5) | 4.3% | — | Bare Concept Media Pheap CMS | 1/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter. | |
| Modificada | Media (5.1) | 1.7% | — | Planet Concept Planetgallery | 24/7/2006 | 16/6/2026 | admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uploading files with a double extension and directly accessing the file in the images directory, which bypasses a regular expression check for safe file types. | |
| Modificada | Alta (10) | 6.2% | — | Planet Concept Planetnews | 13/7/2006 | 16/6/2026 | PlaNet Concept planetNews allows remote attackers to bypass authentication and execute arbitrary code via a direct request to news/admin/planetnews.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Planet Concept Planetstat | 12/5/2006 | 16/6/2026 | PlaNet Concept plaNetStat 20050127 allows remote attackers to gain administrative privileges, and view and configure log files, via a direct request to the (1) admin.php or (2) settings.php page. | |
| Modificada | Alta (7.5) | 2.7% | — | Planet Concept Planetgallery | 1/5/2006 | 16/6/2026 | planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php. | |
| Modificada | Media (4.3) | 1.9% | — | Planet Concept Planetsearch+ | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter. | |
| Modificada | Media (4.6) | 0.34% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Nexus Concepts Dev Hound 2.24 and earlier stores username and password information in cleartext in the devhound.tdbd file, which allows local users to gain privileges. | |
| Modificada | Media (4.3) | 1.2% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Nexus Concepts Dev Hound 2.24 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple unspecified user input fields. | |
| Modificada | Media (5) | 1.4% | — | Nexus Concepts DEV Hound | 23/12/2005 | 16/6/2026 | Nexus Concepts Dev Hound 2.24 and earlier allows remote attackers to obtain the installation path via a URL containing a non-existent .dll file. | |
| Modificada | Media (4.3) | 1.8% | — | Binary-concepts Binary Board System | 17/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Binary Board System (BBS) 0.2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) inreplyto, (2) article, and (3) board parameters to reply.pl, (4) branch, (5) board, and (6) stats.pl parameters to (b) stats.pl, and (7) board… | |
| Modificada | Alta (7.5) | 1.3% | — | Wwweb Concepts Events System | 5/6/2005 | 16/6/2026 | SQL injection vulnerability in login.asp for WWWeb Concepts Events System 1.0 allows remote attackers to execute arbitrary SQL commands via the password. | |
| Modificada | Media (5) | 3.1% | — | Conceptronic Cadslr1 Adsl Router | 31/12/2004 | 16/6/2026 | The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username. | |
| Modificada | Media (5) | 7.4% | — | Generation Terrorists Designs AND Concepts Sojourn | 14/3/2000 | 16/6/2026 | Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack. |