Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

622 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)1.2%—Steven Jones Context19/5/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.
ModificadaAlta (7.5)1.00%💥 ExploitCmsnx Million Dollar Text Links4/12/200916/6/2026
SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)2.5%💥 ExploitTurnkeyforms Text Link Sales13/8/200916/6/2026
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privileges via a direct request.
ModificadaAlta (7.5)2.4%💥 ExploitCmsnx Million Dollar Text Links1/6/200916/6/2026
Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.
ModificadaAlta (7.5)2.8%💥 ExploitKalptarudemos Million Dollar Text Links7/5/200916/6/2026
Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.
ModificadaMedia (4.3)2.2%💥 ExploitRightscripts Text Lines Rearrange Script27/2/200916/6/2026
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled, allows remote attackers to read arbitrary local files via directory traversal sequences in the filename parameter.
ModificadaMedia (4.3)1.2%—Subtextproject Subtext25/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in Subtext 2.0 allows remote attackers to inject arbitrary web script or HTML via a comment, related to "the feature which converts URLs to anchor tags."
ModificadaAlta (7.5)0.91%💥 ExploitHispah Text Links ADS16/2/200916/6/2026
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitHispah Text Links ADS16/2/200916/6/2026
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.
ModificadaAlta (7.5)1.4%—Futomis CGI Cafe Fulltext Search CGI10/2/200916/6/2026
Unspecified vulnerability in futomi's CGI Cafe Fulltext search CGI 1.1.2 allows remote attackers to gain administrative privileges via unknown vectors.
ModificadaAlta (7.5)39%💥 ExploitMariovaldez Simple Text-file Login Script30/12/200816/6/2026
PHP remote file inclusion vulnerability in slogin_lib.inc.php in Simple Text-File Login Script (SiTeFiLo) 1.0.6 allows remote attackers to execute arbitrary PHP code via a URL in the slogin_path parameter.
ModificadaMedia (5)2.6%💥 ExploitMariovaldez Simple Text-file Login Script30/12/200816/6/2026
Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for slog_users.txt.
ModificadaBaja (3.5)0.89%—Textpattern30/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in textarea/index.php in Textpattern (aka Txp CMS) 4.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Body parameter in an article action. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)1.2%—Textpattern19/12/200816/6/2026
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.
ModificadaMedia (5)1.5%—Textpattern19/12/200816/6/2026
index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long message parameter.
ModificadaMedia (4.3)1.1%—Textpattern19/12/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section.
ModificadaMedia (4.3)1.6%💥 ExploitTurnkeyforms Text Link Sales12/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitTurnkeyforms Text Link Sales12/12/200816/6/2026
SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitYourfreeworld Scrolling Text ADS Script4/11/200816/6/2026
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)0.95%💥 ExploitYourfreeworld Stylish Text ADS Script21/8/200816/6/2026
SQL injection vulnerability in trl.php in YourFreeWorld Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.3%—Webwizguide WEB WIZ Rich Text Editor30/7/200816/6/2026
Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
ModificadaMedia (4.3)1.1%—Opentext Livelink ECM14/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through 9.7.0 and possibly earlier does not set the charset, which allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input.
ModificadaMedia (6.4)2.6%💥 ExploitWEB WIZ Rich Text Editor29/1/200816/6/2026
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.
ModificadaMedia (5)3.9%💥 ExploitWEB WIZ Rich Text Editor29/1/200816/6/2026
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the sub parameter in a save action.
ModificadaMedia (5)4.9%💥 ExploitWebwiz WEB WIZ ForumsWebwiz WEB WIZ NewspadWebwiz WEB WIZ Rich Text Editor29/1/200816/6/2026
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a…
Orbitaley — Vulnerabilidades