Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3072▲ 483 respecto a la semana anterior
Críticas / altas1456▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.43% | — | Phpjabbers Business Directory Script | 30/8/2023 | 17/6/2026 | Business Directory Script 3.2 de PHPJabbers es vulnerable a Cross Site Scripting (XSS) a través del parámetro keyword. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Ticket Support Script | 28/8/2023 | 17/6/2026 | User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers CAR Rental Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phpjabbers Taxi Booking Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Fundraising Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Yacht Listing Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Restaurant Booking Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Crítica (9.8) | 0.89% | — | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Alta (8.8) | 0.96% | — | Phpjabbers CAR Rental Script | 28/8/2023 | 17/6/2026 | In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | |
| Modificada | Media (5.4) | 1.1% | 💥 Exploit | Phpjabbers Ticket Support Script | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2. | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Phpjabbers Fundraising Script | 28/8/2023 | 17/6/2026 | PHPJabbers Fundraising Script v1.0 is vulnerable to Cross Site Scripting (XSS) via the "action" parameter of index.php. | |
| Modificada | Media (6.1) | 1.0% | 💥 Exploit | Phpjabbers Yacht Listing Script | 28/8/2023 | 17/6/2026 | There is a Cross Site Scripting (XSS) vulnerability in the "action" parameter of index.php in PHPJabbers Yacht Listing Script v1.0. | |
| Modificada | Crítica (9.8) | 3.7% | 💥 Exploit | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Phpjabbers Food Delivery Script | 28/8/2023 | 17/6/2026 | PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. | |
| Modificada | Media (5.5) | 0.34% | — | Artifex GhostscriptRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR IBM Z Systems+5 | 23/8/2023 | 17/6/2026 | A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8. | |
| Modificada | Alta (7.8) | 0.24% | — | Redhat Subscription-managerFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+16 | 23/8/2023 | 17/6/2026 | A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a… | |
| Modificada | Alta (7.8) | 0.81% | — | Artifex Ghostscript | 22/8/2023 | 17/6/2026 | Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via opening of crafted PDF document. | |
| Modificada | Media (5.5) | 0.70% | — | Artifex Ghostscript | 22/8/2023 | 17/6/2026 | A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file. | |
| Modificada | Crítica (9.8) | 1.5% | — | Jerryscript | 21/8/2023 | 17/6/2026 | Una vulnerabilidad de desbordamiento de búfer en JerryScript Project jerryscript v3.0.0 permite a un atacante remoto ejecutar código arbitrario a través del componente "scanner_is_context_needed" en "js-scanner-until.c". | |
| Modificada | Crítica (9.8) | 7.9% | 💥 Exploit | Campcodes Complete Online Matrimonial Website System Script | 16/8/2023 | 17/6/2026 | install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. | |
| Modificada | Media (6.1) | 0.41% | — | I13websolution Email Subscription Popup | 14/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento I Thirteen Web Solution Email Subscription Popup versiones <= 1.2.16. | |
| Modificada | Media (5.5) | 0.33% | — | Jerryscript | 11/8/2023 | 17/6/2026 | An issue was discovered in ecma-helpers.c in jerryscript version 2.3.0, allows local attackers to cause a denial of service (DoS) (Null Pointer Dereference). | |
| Modificada | Crítica (9.8) | 1.0% | — | Phpjabbers Ticket Support Script | 10/8/2023 | 17/6/2026 | Una vulnerabilidad de carga de archivos en PHPJabbers Ticket Support Script v3.2 permite a atacantes ejecutar código arbitrario cargando un archivo manipulado. | |
| Modificada | Alta (7.5) | 0.73% | — | Phpjabbers Yacht Listing Script | 10/8/2023 | 17/6/2026 | una filtración de información en PHPJabbers Yacht Listing Script v1.0 permite a los atacantes exportar los números de tarjetas de crédito de los clientes desde el módulo de Reservas. | |
| Modificada | Media (6.1) | 0.38% | — | Simplecoding Terms Descriptions | 10/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vladimir Statsenko Terms descriptions plugin <= 3.4.4 versions. |