Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | Phpwebsite | 20/10/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar module, (2) the fatcat_id parameter in the fatcat module, (3) the PAGE_id parameter in the pagemaster module, (4) the PDA_limit parameter… | |
| Modificada | Media (5) | 1.3% | — | Phpwebsite | 20/10/2003 | 16/6/2026 | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to obtain the full pathname of phpWebSite via an invalid year, which generates an error from localtime() in TimeZone.php of the Pear library. | |
| Modificada | Alta (7.8) | 1.5% | — | Phpwebsite | 20/10/2003 | 16/6/2026 | The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter. | |
| Modificada | Media (5) | 2.8% | — | Deerfield Visnetic Website | 18/8/2003 | 16/6/2026 | VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error message, as demonstrated using _vti_bin/fpcount.exe. | |
| Modificada | Media (5) | 1.2% | — | Deerfield Website PRO | 31/12/2002 | 16/6/2026 | WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Phpwebsite | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute arbitrary Javascript script via the sid parameter, as demonstrated using an IMG tag. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Deerfield Visnetic Website | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) to a non-existent page, which is injected into the resulting 404 error page. | |
| Modificada | Media (4.3) | 1.2% | — | Phpwebsite | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpWebSite 0.8.3 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | |
| Modificada | Media (5) | 1.6% | — | Deerfield Visnetic Website | 31/12/2002 | 16/6/2026 | Buffer overflow in httpd32.exe in Deerfield VisNetic WebSite before 3.5.15 allows remote attackers to cause a denial of service (crash) via a long HTTP OPTIONS request. | |
| Modificada | Alta (7.5) | 6.6% | 💥 Exploit | Phpwebsite | 4/10/2002 | 16/6/2026 | modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malicious code. | |
| Modificada | Media (5) | 1.6% | — | Oreilly Website PRO | 22/8/2001 | 16/6/2026 | Remote manager service in Website Pro 3.0.37 allows remote attackers to cause a denial of service via a series of malformed HTTP requests to the /dyn directory. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Oreilly Website Professional | 22/8/2001 | 16/6/2026 | O'Reilly Website Professional 2.5.4 and earlier allows remote attackers to determine the physical path to the root directory via a URL request containing a ":" character. | |
| Modificada | Alta (10) | 1.5% | — | Phpwebsite Development Team Phpwebsite | 19/7/2001 | 16/6/2026 | Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges. | |
| Modificada | Alta (7.5) | 1.4% | — | Oreilly Website PRO | 20/10/2000 | 16/6/2026 | O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Oreilly Website Professional | 19/7/2000 | 16/6/2026 | Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execute arbitrary commands via a URL containing a long "keywords" parameter. | |
| Modificada | Alta (10) | 5.3% | — | Oreilly Website Professional | 17/7/2000 | 16/6/2026 | Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header. | |
| Modificada | Alta (7.5) | 2.0% | — | Baron Consulting Group Websitetool | 1/2/2000 | 16/6/2026 | The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | |
| Modificada | Media (5) | 2.0% | — | Oreilly Website Professional | 13/1/2000 | 16/6/2026 | WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request. | |
| Modificada | Media (5) | 1.7% | — | Oreilly WebsiteOreilly Website PRO | 16/2/1999 | 16/6/2026 | O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat. | |
| Modificada | Alta (7.5) | 2.0% | — | Oreilly Website | 1/9/1997 | 16/6/2026 | The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Oreilly Website | 1/1/1997 | 16/6/2026 | Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string. |