Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
866 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Joomla! | 7/10/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.5.12 allow remote attackers to inject arbitrary web script or HTML via the HTTP_REFERER header to (1) components/com_content/views/article/tmpl/form.php, (2) components/com_user/controller.php, (3) plugins/system/legacy/html.php, or (4)… | |
| Modificada | Media (4.3) | 1.3% | — | Joomla! | 26/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Joomla! | 26/9/2012 | 16/6/2026 | SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | Joomla! | 6/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the update manager in Joomla! 2.5.x before 2.5.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Joomla! | 6/9/2012 | 16/6/2026 | Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via unknown attack vectors. NOTE: this might be a duplicate of CVE-2012-1599. | |
| Modificada | Media (5) | 1.3% | — | Joomla! | 6/9/2012 | 16/6/2026 | Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain the installation path via unspecified vectors related to "administrator." | |
| Modificada | Media (5) | 1.3% | — | Joomla! | 6/9/2012 | 16/6/2026 | Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 allows attackers to read the error log via unknown vectors. | |
| Modificada | Media (5) | 1.3% | — | Joomla! | 6/9/2012 | 16/6/2026 | Unspecified vulnerability in Joomla! 1.7.x before 1.7.5 and 2.5.x before 2.5.1 allows attackers to obtain sensitive information via unknown vectors related to "administrator." | |
| Modificada | Media (4.3) | 1.6% | — | Joomla! | 6/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Joomla! 1.6 and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0820. | |
| Modificada | Media (5) | 1.9% | — | Joomla! | 6/9/2012 | 16/6/2026 | Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0819. | |
| Modificada | Media (4.3) | 1.6% | — | Joomla! | 6/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0822. | |
| Modificada | Media (5) | 1.9% | — | Joomla! | 6/9/2012 | 16/6/2026 | Unspecified vulnerability in Joomla! 1.6.x and 1.7.x before 1.7.4 allows remote attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2012-0821. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Joomla COM Weblinks | 6/9/2012 | 16/6/2026 | SQL injection vulnerability in the Weblinks (com_weblinks) component for Joomla! and Mambo 1.0.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter. | |
| Modificada | Media (5) | 1.3% | — | Joomla! | 3/7/2012 | 16/6/2026 | Joomla! 2.5.3 allows remote attackers to obtain the installation path via the Host HTTP Header. | |
| Modificada | Media (4.3) | 1.8% | — | Joomla! | 3/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Joomla! 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the Host HTTP Header. | |
| Modificada | Media (5) | 1.6% | — | Joomla! | 3/7/2012 | 16/6/2026 | Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to obtain sensitive information via vectors related to "Inadequate filtering" and a "SQL error." | |
| Modificada | Alta (7.5) | 2.3% | — | Joomla! | 3/7/2012 | 16/6/2026 | Unspecified vulnerability in Joomla! 2.5.x before 2.5.5 allows remote attackers to gain privileges via unknown attack vectors related to "Inadequate checking." | |
| Modificada | Media (6) | 1.0% | — | Ryan Demmer Joomla Content Editor | 21/5/2012 | 16/6/2026 | Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the Joomla Content Editor (JCE) component before 2.1 for Joomla!, when chunking is set to greater than zero, allows remote authors to execute arbitrary PHP code by uploading a PHP file with a double extension as demonstrated by .jpg.pht. | |
| Modificada | Media (4.3) | 1.1% | — | Ryan Demmer Joomla Content Editor | 21/5/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Profile List in the Joomla Content Editor (JCE) component before 2.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the search parameter to administrator/index.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Extensionsforjoomla COM Vikrealestate | 15/12/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Joomlaextensions COM Hmcommunity | 14/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) language[], (2) university[], (3) persent[], (4) company_name[], (5) designation[], (6) music[], (7) books[], (8)… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Joomlaextensions COM Hmcommunity | 14/12/2011 | 16/6/2026 | SQL injection vulnerability in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a fnd_home action to index.php. | |
| Modificada | Media (4.3) | 1.1% | — | Joomla! | 23/11/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.6.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 0.94% | — | Joomla! | 23/11/2011 | 16/6/2026 | The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Joomlatune COM Jcomments | 23/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.jcomments.php in the JoomlaTune JComments (com_jcomments) component 2.1.0.0 for Joomla! allows remote authenticated users to inject arbitrary web script or HTML via the name parameter to index.php. |