Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 1.2% | — | Steven Jones Context | 19/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Cmsnx Million Dollar Text Links | 4/12/2009 | 16/6/2026 | SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Turnkeyforms Text Link Sales | 13/8/2009 | 16/6/2026 | admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Cmsnx Million Dollar Text Links | 1/6/2009 | 16/6/2026 | Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Kalptarudemos Million Dollar Text Links | 7/5/2009 | 16/6/2026 | Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Rightscripts Text Lines Rearrange Script | 27/2/2009 | 16/6/2026 | Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled, allows remote attackers to read arbitrary local files via directory traversal sequences in the filename parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Subtextproject Subtext | 25/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Subtext 2.0 allows remote attackers to inject arbitrary web script or HTML via a comment, related to "the feature which converts URLs to anchor tags." | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Hispah Text Links ADS | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Hispah Text Links ADS | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idcat parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Futomis CGI Cafe Fulltext Search CGI | 10/2/2009 | 16/6/2026 | Unspecified vulnerability in futomi's CGI Cafe Fulltext search CGI 1.1.2 allows remote attackers to gain administrative privileges via unknown vectors. | |
| Modificada | Alta (7.5) | 39% | 💥 Exploit | Mariovaldez Simple Text-file Login Script | 30/12/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Mariovaldez Simple Text-file Login Script | 30/12/2008 | 16/6/2026 | Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt. | |
| Modificada | Baja (3.5) | 0.89% | — | Textpattern | 30/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in textarea/index.php in Textpattern (aka Txp CMS) 4.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Body parameter in an article action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.2% | — | Textpattern | 19/12/2008 | 16/6/2026 | Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session. | |
| Modificada | Media (5) | 1.5% | — | Textpattern | 19/12/2008 | 16/6/2026 | index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long message parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Textpattern | 19/12/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Turnkeyforms Text Link Sales | 12/12/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Turnkeyforms Text Link Sales | 12/12/2008 | 16/6/2026 | SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Yourfreeworld Scrolling Text ADS Script | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Yourfreeworld Stylish Text ADS Script | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in trl.php in YourFreeWorld Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Webwizguide WEB WIZ Rich Text Editor | 30/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Opentext Livelink ECM | 14/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through 9.7.0 and possibly earlier does not set the charset, which allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input. | |
| Modificada | Media (6.4) | 2.6% | 💥 Exploit | WEB WIZ Rich Text Editor | 29/1/2008 | 16/6/2026 | RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors. | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | WEB WIZ Rich Text Editor | 29/1/2008 | 16/6/2026 | Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action. | |
| Modificada | Media (5) | 4.9% | 💥 Exploit | Webwiz WEB WIZ ForumsWebwiz WEB WIZ NewspadWebwiz WEB WIZ Rich Text Editor | 29/1/2008 | 16/6/2026 | Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a… |