Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Insane Visions Onecms | 20/9/2007 | 16/6/2026 | SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Insanely Simple Blog | 18/7/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to execute arbitrary SQL commands via the current_subsection parameter to index.php and other unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Insanely Simple Blog | 18/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Insanely Simple Blog 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the search action, possibly related to the term parameter to index.php; or (2) an anonymous blog entry, possibly involving the (a) posted_by, (b) subject,… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Insane Visions Blogphp | 22/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | Insane Visions Blogphp | 19/1/2006 | 16/6/2026 | SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action. | |
| Modificada | Alta (10) | 4.2% | — | Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+2 | 13/7/2005 | 16/6/2026 | The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the… | |
| Modificada | Media (5) | 1.8% | — | SaneSane-backend | 22/9/2003 | 16/6/2026 | saned in sane-backends 1.0.7 and earlier, when debug messages are enabled, does not properly handle dropped connections, which can prevent strings from being null terminated and cause a denial of service (segmentation fault). | |
| Modificada | Alta (7.5) | 1.9% | — | SaneSane-backend | 22/9/2003 | 16/6/2026 | saned in sane-backends 1.0.7 and earlier does not check the IP address of the connecting host during the SANE_NET_INIT RPC call, which allows remote attackers to use that call even if they are restricted in saned.conf. | |
| Modificada | Media (5) | 1.8% | — | SaneSane-backend | 22/9/2003 | 16/6/2026 | saned in sane-backends 1.0.7 and earlier, and possibly later versions, does not properly allocate memory in certain cases, which could allow attackers to cause a denial of service (memory consumption). | |
| Modificada | Alta (7.5) | 1.8% | — | SaneSane-backend | 22/9/2003 | 16/6/2026 | saned in sane-backends 1.0.7 and earlier does not properly "check the validity of the RPC numbers it gets before getting the parameters," with unknown consequences. | |
| Modificada | Media (5) | 2.1% | — | SaneSane-backend | 22/9/2003 | 16/6/2026 | saned in sane-backends 1.0.7 and earlier calls malloc with an arbitrary size value if a connection is dropped before the size value has been sent, which allows remote attackers to cause a denial of service (memory consumption or crash). | |
| Modificada | Alta (7.5) | 2.1% | — | SaneSane-backend | 22/9/2003 | 16/6/2026 | saned in sane-backends 1.0.7 and earlier does not quickly handle connection drops, which allows remote attackers to cause a denial of service (segmentation fault) when invalid memory is accessed. | |
| Modificada | Alta (7.5) | 4.0% | — | Apache Http ServerUsanet Creations Makebid Auction Deluxe | 29/5/2002 | 16/6/2026 | Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3,… | |
| Modificada | Baja (1.2) | 0.32% | — | Oliver Rauch Xsane | 15/1/2002 | 16/6/2026 | xSANE 0.81 and earlier allows local users to modify files of other xSANE users via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 0.38% | — | Sane | 11/12/2001 | 16/6/2026 | Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files. | |
| Modificada | Alta (7.2) | 0.35% | — | Mostang Sane | 19/7/2001 | 16/6/2026 | Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned. |