Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 23% | — | Opendocman | 7/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Opendocman | 10/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in odm-init.php in OpenDocMan before 1.2.7.3 allows remote authenticated users to inject arbitrary web script or HTML via the file name of an uploaded file. | |
| Modificada | Media (6.8) | 1.2% | 💥 Exploit | Opendocman | 9/3/2014 | 17/6/2026 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Opendocman | 9/3/2014 | 17/6/2026 | SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Photoindochina COM Restaurantguide | 9/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML by placing it after a > (greater than) character. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Photoindochina COM Restaurantguide | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a country action to index.php. | |
| Modificada | Media (5) | 1.4% | — | Opendocman | 24/9/2011 | 16/6/2026 | OpenDocMan 1.2.6-svn-2011-01-21 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by User_Perms_class.php and certain other files. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Photoindochina COM Golfcourseguide | 30/7/2010 | 16/6/2026 | SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a golfcourses action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | — | Opendocman | 27/10/2009 | 16/6/2026 | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 2.8% | 💥 Exploit | Opendocman | 26/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7)… | |
| Modificada | Alta (7.5) | 1.2% | — | Opendocman | 26/10/2009 | 16/6/2026 | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Opendocman | 20/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Opendocman | 20/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in out.php in OpenDocMan 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the last_message parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Opendocman | 3/11/2006 | 16/6/2026 | SQL injection vulnerability in index.php in OpenDocMan 1.2p3 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Opendoc Fullcore | 18/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) sw/index_sw.php; (2) cart.php, (3) lib_cart.php, (4) lib_read_cart.php, (5) lib_sys_cart.php, and (6) txt_info_cart.php in… | |
| Modificada | Media (5.1) | 3.9% | 💥 Exploit | Opendock Easy Gallery | 12/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) file.php; (2) find_user.php, (3) lib_user.php, (4) lib_form_user.php, and (5) user.php in… | |
| Modificada | Media (5.1) | 3.7% | 💥 Exploit | Opendock Easy Blog | 12/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3) find_file.php, (4) lib_read_file.php, and (5)… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Opendock Easy DOC | 12/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3) find_file.php, (4) lib_file.php, and (5) lib_form_file.php in… | |
| Modificada | Media (5) | 1.4% | — | Zendocs Zentrack | 31/12/2002 | 16/6/2026 | zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message. |