Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Jonas Renggli Vshoutbox | 17/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the vShoutbox (vshoutbox) extension 0.0.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 3.6% | 💥 Exploit | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Maniacomputer Mcshoutbox | 16/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Turtushout | 24/9/2009 | 16/6/2026 | SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Mark Girling Myshoutpro | 21/4/2009 | 16/6/2026 | MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_access cookie to 1. | |
| Modificada | Media (4.3) | 0.85% | — | Mark Girling Myshoutpro | 21/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyShoutPro before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Comicshout | 6/3/2009 | 16/6/2026 | SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Prezmo Small Shoutbox | 26/2/2009 | 16/6/2026 | SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter in a delete action. | |
| Modificada | Media (5) | 1.2% | — | Designplace Asp/ms Access Shoutbox | 9/10/2008 | 16/6/2026 | ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Shoutcastadmin Wallcity-server Shoutcast Admin Panel | 23/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WallCity-Server Shoutcast Admin Panel 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter to the login interface. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Shoutcastadmin Wallcity-server Shoutcast Admin Panel | 23/6/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in WallCity-Server Shoutcast Admin Panel 2.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Comicshout | 27/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL commands via the comic_id parameter. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Phphq Phshoutbox Final | 27/4/2008 | 16/6/2026 | phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php. | |
| Modificada | Media (4.3) | 1.2% | — | Simple Machines SMF Shoutbox | 14/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";". | |
| Modificada | Media (4.3) | 1.0% | — | Geek-palace.com Lineshout | 20/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in shout.php (aka the shoutbox) in LineShout 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username (nickname) or (2) message parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.1% | — | Drupal Shoutbox | 10/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Shoutbox module for Drupal 5.x before Shoutbox 5.x-1.1 allows remote authenticated users to inject arbitrary web script or HTML via Shoutbox block messages. | |
| Modificada | Media (4.3) | 1.1% | — | Script-fun Sf-shoutbox | 14/11/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in main.php in SF-Shoutbox 1.2.1 through 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) nick (aka Name) and (2) shout (aka Shout) parameters. | |
| Modificada | Media (4.3) | 1.1% | — | Dscripting.com D22-shoutbox | 22/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in D22-Shoutbox for Invision Power Board (IPB or IP.Board) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Mapos Scripts Shoutbox | 14/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | |
| Modificada | Alta (7.5) | 46% | 💥 Exploit | Shoutpro | 19/4/2007 | 16/6/2026 | Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shouts.php via the shout parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Nullsoft Shoutcast Server | 2/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level URI on the Incoming interface (port 8001/tcp), which is not properly handled in the administrator interface when viewing the log file. | |
| Modificada | Media (5) | 2.5% | — | Shoutpro | 24/2/2007 | 16/6/2026 | include.php in Shoutpro 1.0 might allow remote attackers to bypass IP ban restrictions via a URL in the path parameter that points to an alternate bannedips.php file. NOTE: this issue was originally reported as remote file inclusion, but CVE analysis suggests that this cannot be used for code execution. | |
| Modificada | Alta (7.8) | 1.5% | — | Toxiclab Shoutbox | 29/1/2007 | 16/6/2026 | Toxiclab Shoutbox 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db.mdb. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Knusperleicht Shoutbox | 23/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in shout.php in Knusperleicht ShoutBox 2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) sbNick or (2) sbKommentar parameter. |