Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Weblog | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Weblog 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to admin/index.php in a blogs search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter to… | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Greeting | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Greeting 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script and (2) msg_script2 parameters. | |
| Modificada | Alta (7.5) | 1.1% | — | Maianscriptworld Maian Search | 14/5/2008 | 16/6/2026 | SQL injection vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action. | |
| Modificada | Alta (7.5) | 1.1% | — | Maianscriptworld Maian Music | 14/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Maian Music 1.1 allows remote attackers to execute arbitrary SQL commands via the album parameter in an album action. | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Links | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Links 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script2 and (2) msg_script3 parameters. | |
| Modificada | Media (4.3) | 1.0% | — | Maianscriptworld Maian Search | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/header.php in Maian Search 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) header, (2) header2, (3) header3, (4) header4, (5) header5, (6) header6, (7) header7, (8) header8, and (9) header9 parameters. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Maianscriptworld Maian Uploader | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/admin/index.php in a search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter… | |
| Modificada | Alta (7.5) | 1.1% | — | Maianscriptworld Maian Greeting | 14/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Maian Greeting 2.1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search action. | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Guestbook | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Guestbook 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script2 and (2) msg_script3 parameters. | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Music | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Music 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter in a search action to index.php, and the (2) msg_script parameter to admin/inc/footer.php. | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Gallery | 14/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/index.php in Maian Gallery 2.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action. | |
| Modificada | Media (4.3) | 1.0% | — | Maianscriptworld Maian Cart | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Cart 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_adminheader, (2) msg_adminheader2, (3) msg_adminheader3, (4) msg_adminheader4, and unspecified other parameters to admin/inc/header.php; the (5) msg_script3 and… | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Support | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Support 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script, (2) msg_script2, and (3) msg_script3 parameters to admin/inc/footer.php; and the (4) msg_script2 parameter to admin/inc/header.php. | |
| Modificada | Media (4.3) | 0.84% | — | Maianscriptworld Maian Cart | 29/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Maian Cart 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search command. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 2.6% | — | Maia Mailguard | 9/7/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in Maia Mailguard 1.0.2 and earlier might allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) prevlang and (2) super parameters to (a) php/login.php; the (3) charset parameter to (a) php/login.php, (b) php/internal-init.php, and (c) php/xlogin.php;… | |
| Modificada | Media (5) | 8.9% | 💥 Exploit | Maia Mailguard | 9/7/2007 | 16/6/2026 | Directory traversal vulnerability in login.php in Maia Mailguard 1.0.2 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. | |
| Modificada | Media (6.8) | 1.7% | — | Maian Weblog | 18/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Maian Weblog 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, since the path_to_folder variable is initialized before use | |
| Modificada | Alta (7.5) | 1.7% | — | Maian Search | 18/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in search.php in Maian Search 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this issue was fixed last year and [no] is longer a… | |
| Modificada | Media (6.8) | 1.7% | — | Maian Gallery | 18/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Maian Gallery 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. NOTE: this issue was disputed by a third party researcher, but confirmed by the vendor, stating "this problem existed only briefly in v1.0." | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Maian Recipe | 8/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Maian Events | 21/3/2006 | 16/6/2026 | SQL injection vulnerability in events.php in Maian Events 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. | |
| Modificada | Media (6.4) | 2.4% | 💥 Exploit | Maian Script World Maian Weblog | 21/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Maian Weblog 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) entry and (2) email parameters to (a) print.php and (b) mail.php. | |
| Modificada | Alta (7.5) | 2.1% | — | Maian Support | 19/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Maian Support 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) pass parameter to admin/index.php. |