Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Steveyolam Tinyguestbook23/9/201216/6/2026
Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.2%—Steveyolam Tinyguestbook23/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaMedia (4.3)1.6%💥 ExploitWinn Guestbook29/12/201116/6/2026
Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.00%💥 ExploitEsoftpro Online Guestbook PRO1/11/201116/6/2026
SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.
ModificadaAlta (7.5)0.99%💥 ExploitKmsoft Guestbook1/11/201116/6/2026
SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter.
ModificadaAlta (7.5)1.6%💥 ExploitHarmistechnology COM Jeguestbook5/10/201116/6/2026
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the d_itemid parameter in an item_detail action to index.php.
ModificadaMedia (4.3)1.1%—Mrcgiguy Guestbook1/12/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in gb.cgi in MRCGIGUY (MCG) Guestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) website, and (4) message parameters.
ModificadaAlta (7.5)0.92%💥 ExploitEsoftpro Online Guestbook PRO12/7/201016/6/2026
SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the display parameter.
ModificadaMedia (5)2.6%💥 ExploitWinn ASP Guestbook29/3/201016/6/2026
Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb.
ModificadaMedia (5)2.5%💥 ExploitKmsoft Guestbook16/3/201016/6/2026
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb.
ModificadaAlta (7.5)0.93%💥 ExploitHypersilence Silentum Guestbook10/3/201016/6/2026
SQL injection vulnerability in silentum_guestbook.php in Silentum Guestbook 2.0.2 allows remote attackers to execute arbitrary SQL commands via the messageid parameter.
ModificadaMedia (4.3)1.7%—Sanusart Simple PHP Guestbook8/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in guestbook.php in Simple PHP Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
ModificadaMedia (4.3)1.5%💥 ExploitWinn Guestbook8/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Winn Guestbook 2.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaAlta (7.5)2.6%💥 ExploitJAX Scripts JAX Guestbook29/12/200916/6/2026
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php.
ModificadaMedia (4.3)1.6%💥 ExploitZenas Paobacheca Guestbook30/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.
ModificadaCrítica (9.8)5.0%💥 ExploitZenas Pao-bacheca Guestbook25/9/200916/6/2026
login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.
ModificadaMedia (4.3)1.2%💥 ExploitWebilix Wx-guestbook23/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.93%💥 ExploitWebilix Wx-guestbook23/9/200916/6/2026
Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.5%💥 ExploitDigioz Guestbook15/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.
ModificadaMedia (4.3)1.5%💥 ExploitAlexguestbook @lex Guestbook1/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained…
ModificadaAlta (7.5)2.6%💥 ExploitPhpversion PHP VX Guestbook19/8/200916/6/2026
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.
ModificadaMedia (5)6.6%💥 ExploitPhpversion PHP VX Guestbook19/8/200916/6/2026
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.
ModificadaAlta (7.5)2.9%💥 ExploitSansuart Free Simple Guestbook PHP Script11/8/200916/6/2026
Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some…
ModificadaMedia (5)1.3%—Flashden Guestbook30/7/200916/6/2026
FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo function.
ModificadaMedia (4.3)0.85%—Esoftpro Online Guestbook PRO13/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Orbitaley — Vulnerabilidades