Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Document Creator | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Callback Widget | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Media (6.1) | 1.3% | 💥 Exploit | Phpjabbers Callback Widget | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Callback Widget v1.0. | |
| Modificada | Alta (8.8) | 0.96% | — | Phpjabbers CAR Rental Script | 28/8/2023 | 17/6/2026 | In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | |
| Modificada | Media (5.4) | 1.1% | 💥 Exploit | Phpjabbers Ticket Support Script | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Phpjabbers Make AN Offer Widget | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Make an Offer Widget v1.0. | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Phpjabbers Fundraising Script | 28/8/2023 | 17/6/2026 | PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Phpjabbers Yacht Listing Script | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0. | |
| Modificada | Crítica (9.8) | 3.7% | 💥 Exploit | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Callback Widget | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Callback Widget v1.0. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Callback Widget | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the value-text-o_sms_email_request_message parameters of index.php in PHPJabbers Callback Widget v1.0. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Document Creator | 10/8/2023 | 17/6/2026 | PHPJabbers Document Creator v1.0 is vulnerable to Cross Site Scripting (XSS) via all post parameters of "Export Requests" aside from "request_feed". | |
| Modificada | Media (5.4) | 0.42% | — | Phpjabbers Callback Widget | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the value-enum-o_bf_include_timezone parameter of index.php in PHPJabbers Callback Widget v1.0. | |
| Modificada | Crítica (9.8) | 0.79% | — | Phpjabbers Document Creator | 10/8/2023 | 17/6/2026 | There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Document Creator | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0. | |
| Modificada | Media (6.1) | 0.44% | — | Phpjabbers Document Creator | 10/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Document Creator v1.0. | |
| Modificada | Crítica (9.8) | 1.0% | — | Phpjabbers Ticket Support Script | 10/8/2023 | 17/6/2026 | A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Alta (7.5) | 0.73% | — | Phpjabbers Yacht Listing Script | 10/8/2023 | 17/6/2026 | An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module. | |
| Modificada | Media (6.5) | 0.28% | — | Phpjabbers Class Scheduling System | 8/8/2023 | 17/6/2026 | PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text. | |
| Modificada | Alta (7.5) | 0.48% | — | ABB Ac700f FirmwareABB Freelance 2013ABB Freelance 2016ABB Freelance 2019 | 7/8/2023 | 17/6/2026 | ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product… | |
| Modificada | Alta (7.5) | 0.47% | — | ABB Ac700f FirmwareABB Freelance 2013ABB Freelance 2016ABB Freelance 2019 | 7/8/2023 | 17/6/2026 | ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product… | |
| Modificada | Media (5.3) | 0.58% | — | Phpjabbers Cleaning Business Software | 4/8/2023 | 17/6/2026 | User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.45% | — | Phpjabbers Cleaning Business Software | 4/8/2023 | 17/6/2026 | In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. |