Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.0%—Jonas Renggli Vshoutbox17/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in the vShoutbox (vshoutbox) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)3.6%💥 ExploitManiacomputer Mcshoutbox16/10/200916/6/2026
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/.
ModificadaMedia (6.8)2.0%💥 ExploitManiacomputer Mcshoutbox16/10/200916/6/2026
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaMedia (4.3)1.7%💥 ExploitManiacomputer Mcshoutbox16/10/200916/6/2026
Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.
ModificadaAlta (7.5)0.93%💥 ExploitTurtushout24/9/200916/6/2026
SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.
ModificadaAlta (7.5)2.6%💥 ExploitMark Girling Myshoutpro21/4/200916/6/2026
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1.
ModificadaMedia (4.3)0.85%—Mark Girling Myshoutpro21/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in MyShoutPro before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.2%💥 ExploitComicshout6/3/200916/6/2026
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456.
ModificadaAlta (7.5)0.97%💥 ExploitPrezmo Small Shoutbox26/2/200916/6/2026
SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action.
ModificadaMedia (5)1.2%—Designplace Asp/ms Access Shoutbox9/10/200816/6/2026
ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.
ModificadaMedia (4.3)1.2%💥 ExploitShoutcastadmin Wallcity-server Shoutcast Admin Panel23/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter to the login interface. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)1.9%💥 ExploitShoutcastadmin Wallcity-server Shoutcast Admin Panel23/6/200816/6/2026
Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
ModificadaAlta (7.5)1.2%💥 ExploitComicshout27/5/200816/6/2026
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the comic_id parameter.
ModificadaAlta (7.5)2.2%💥 ExploitPhphq Phshoutbox Final27/4/200816/6/2026
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.
ModificadaMedia (4.3)1.2%—Simple Machines SMF Shoutbox14/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";".
ModificadaMedia (4.3)1.0%—Geek-palace.com Lineshout20/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.1%—Drupal Shoutbox10/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages.
ModificadaMedia (4.3)1.1%—Script-fun Sf-shoutbox14/11/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in main.php in SF-Shoutbox 1.2.1 through 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) nick (aka Name) and (2) shout (aka Shout) parameters.
ModificadaMedia (4.3)1.1%—Dscripting.com D22-shoutbox22/8/200716/6/2026
Cross-site scripting (XSS) vulnerability in D22-Shoutbox for Invision Power Board (IPB or IP.Board) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)2.8%💥 ExploitMapos Scripts Shoutbox14/8/200716/6/2026
PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.
ModificadaAlta (7.5)46%💥 ExploitShoutpro19/4/200716/6/2026
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shouts.php via the shout parameter.
ModificadaMedia (4.3)1.8%💥 ExploitNullsoft Shoutcast Server2/3/200716/6/2026
Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the administrator interface when viewing the log file.
ModificadaMedia (5)2.5%—Shoutpro24/2/200716/6/2026
include.php in Shoutpro 1.0 might allow remote attackers to bypass IP ban restrictions via a URL in the path parameter that points to an alternate bannedips.php file. NOTE: this issue was originally reported as remote file inclusion, but CVE analysis suggests that this cannot be used for code execution.
ModificadaAlta (7.8)1.5%—Toxiclab Shoutbox29/1/200716/6/2026
Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb.
ModificadaMedia (6.8)1.8%💥 ExploitKnusperleicht Shoutbox23/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter.
Orbitaley — Vulnerabilidades