Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.80% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack. | |
| Modificada | Media (6.1) | 0.82% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack. | |
| Modificada | Media (6.1) | 0.82% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | |
| Modificada | Media (6.1) | 0.80% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack. | |
| Modificada | Media (6.1) | 1.2% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. | |
| Modificada | Alta (7.5) | 1.3% | — | Sabreairlinesolutions Crew ManagementSabreairlinesolutions Crew OperationsSabreairlinesolutions Crew PlanningSabreairlinesolutions Crew Services+1 | 26/7/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. | |
| Modificada | Media (4.3) | 1.4% | — | Lucidcrew Pixie | 4/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Getpixie PixieLucidcrew Pixie | 8/12/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI. | |
| Modificada | Media (5) | 1.9% | — | Lucidcrew Pixie | 24/9/2011 | 16/6/2026 | Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Screwturn Wiki | 5/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary web script or HTML via error messages in the "/admin.aspx - System Log" page. | |
| Modificada | Alta (7.5) | 1.2% | — | SAM Crew Myblog | 12/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the id parameter, a different vector than CVE-2007-1968. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (4.3) | 0.89% | — | SAM Crew Myblog | 11/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/modify.php in Sam Crew MyBlog remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (6.8) | 3.3% | 💥 Exploit | SAM Crew Myblog | 11/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attackers to execute arbitrary PHP code via a URL in the scoreid parameter. |