Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Steveyolam Tinyguestbook | 23/9/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in sign.php in tinyguestbook allow remote attackers to execute arbitrary SQL commands via the (1) name and (2) msg parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | Steveyolam Tinyguestbook | 23/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign.php in tinyguestbook allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Winn Guestbook | 29/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the addPost function in data/functions.php in Winn GuestBook before 2.4.8d allows remote attackers to inject arbitrary web script or HTML via the name parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Esoftpro Online Guestbook PRO | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in ogp_show.php in esoftpro Online Guestbook Pro 5.1 allows remote attackers to execute arbitrary SQL commands via the search parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Kmsoft Guestbook | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in default.asp in KMSoft Guestbook (aka GBook) allows remote attackers to execute arbitrary SQL commands via the p parameter. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Harmistechnology COM Jeguestbook | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the d_itemid parameter in an item_detail action to index.php. | |
| Modificada | Media (4.3) | 1.1% | — | Mrcgiguy Guestbook | 1/12/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in gb.cgi in MRCGIGUY (MCG) Guestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) website, and (4) message parameters. | |
| Modificada | Alta (7.5) | 0.92% | 💥 Exploit | Esoftpro Online Guestbook PRO | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL commands via the display parameter. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Winn ASP Guestbook | 29/3/2010 | 16/6/2026 | Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Kmsoft Guestbook | 16/3/2010 | 16/6/2026 | KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Hypersilence Silentum Guestbook | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in silentum_guestbook.php in Silentum Guestbook 2.0.2 allows remote attackers to execute arbitrary SQL commands via the messageid parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Sanusart Simple PHP Guestbook | 8/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guestbook.php in Simple PHP Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Winn Guestbook | 8/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Winn Guestbook 2.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | JAX Scripts JAX Guestbook | 29/12/2009 | 16/6/2026 | Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.php. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Zenas Paobacheca Guestbook | 30/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php. | |
| Modificada | Crítica (9.8) | 5.0% | 💥 Exploit | Zenas Pao-bacheca Guestbook | 25/9/2009 | 16/6/2026 | login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Webilix Wx-guestbook | 23/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Webilix Wx-guestbook | 23/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Digioz Guestbook | 15/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Alexguestbook @lex Guestbook | 1/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Phpversion PHP VX Guestbook | 19/8/2009 | 16/6/2026 | Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1. | |
| Modificada | Media (5) | 6.6% | 💥 Exploit | Phpversion PHP VX Guestbook | 19/8/2009 | 16/6/2026 | Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Sansuart Free Simple Guestbook PHP Script | 11/8/2009 | 16/6/2026 | Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some… | |
| Modificada | Media (5) | 1.3% | — | Flashden Guestbook | 30/7/2009 | 16/6/2026 | FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo function. | |
| Modificada | Media (4.3) | 0.85% | — | Esoftpro Online Guestbook PRO | 13/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |