Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.6%💥 ExploitAspplayground.net17/8/200616/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en calendar.asp en ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode permite a atacantes remotos inyectar secuecias de comandos web o HTML de su elección mediante el parámetro calendar ID.
ModificadaMedia (5)12%💥 ExploitSkippy.net Wp-db Backup Plugin FOR Wordpress17/8/200616/6/2026
Vulnerabilidad de escalada de directorio en wp_db_backup.php en la extensión Skippy WP-DB-Backup para WordPress 1.7 y anteriores permietn a usuarios autenticados remotamente con privilegios de administración leer archivos de su elección mediante un .. (punto punto) en el parámetro backup de edit.php.
ModificadaAlta (7.5)1.3%💥 ExploitWebvizyon.net Webvizyon Portal11/7/200616/6/2026
Vulnerabilidad de inyección SQL en SayfalaAltList.asp de Webvizyon Portal 2006 permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro ID.
ModificadaMedia (5)37%—Microsoft .net Framework11/7/200616/6/2026
Microsoft .NET framework 2.0 (ASP.NET) en Microsoft Windows 2000 SP4, XP SP1 y SP2, y Server 2003 hasta SP1, permite a atacantes remotos evitar las restricciones de acceso a través de "URL paths" no especificadas que pueden acceder a objetos Application Folder "explícitamente por nombre".
ModificadaMedia (5)1.6%—Lanap Botdetect Captcha Asp.net23/6/200623/9/2026
El componente Lanap BotDetect APS.NET CAPTCHA anterior a v1.5.4.0 almacena el UUID y el hash de un CAPTCHA en la propiedad ViewState de una página, lo cual facilita a los atacantes remotos realizar ataques automatizados "reproduciendo la propiedad ViewState de un nuemro conocido".
ModificadaMedia (5.1)2.1%—Eschew.net Phpbannerexchange19/6/200616/6/2026
Conflictos de interpretación en resetpw.php en phpBannerExchange antes de v2.0 Update 6 permite a atacantes remotos ejecutar comandos SQL a través de un parámetro de correo electrónico que contiene caracteres de valor nulo (%00) después de un e-mail válido. Esto pasa a la comprobación de validación en el comando PHP…
ModificadaAlta (7.5)1.5%—Eschew.net Phpbannerexchange19/6/200616/6/2026
Vulnerabilidad de inyección SQL en phpBannerExchange antes de v2.0 Update 6 permite a atacantes remotos ejecutar comandos SQL a través del parámetro (1) login en (a) client/stats.php y (b) admin/stats.php, o (2) el parámetro pass en client/stats.php.
ModificadaMedia (6.4)1.2%💥 ExploitExpinion.net Multicalendars10/5/200616/6/2026
SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaBaja (2.6)0.90%—Geekforgod.net Prayer Request Board21/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in addRequest.php in Prayer Request Board (PRB) Beta 1 before 20060320 allows remote attackers to inject arbitrary web script or HTML via the Request field.
ModificadaAlta (7.5)1.2%💥 ExploitClanscripte.net Fuju News19/4/200616/6/2026
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (7.5)2.9%💥 ExploitClanscripte.net Fuju News19/4/200616/6/2026
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
ModificadaAlta (7.5)1.1%💥 ExploitPhoetux.net Phxcontacts30/3/200616/6/2026
Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.
ModificadaMedia (4.3)1.4%💥 ExploitPhoetux.net Phxcontacts30/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.
ModificadaMedia (5.1)8.0%—Microsoft .net Framework30/3/200616/6/2026
Buffer overflow in the ILASM assembler in the Microsoft .NET 1.0 and 1.1 Framework might allow user-assisted attackers to execute arbitrary code via a .il file that calls a function with a long name.
ModificadaMedia (4)14%💥 ExploitMicrosoft .net Framework30/3/200616/6/2026
Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.
ModificadaMedia (4.3)1.3%—Xigla Absolute FAQ Manager .net28/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in afmsearch.aspx in Absolute FAQ Manager .NET 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the question parameter.
ModificadaAlta (7.5)59%💥 ExploitMicrosoft Asp.net23/3/200616/6/2026
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several documents that refer to COM components, or are…
ModificadaMedia (4.3)1.3%—Xhawk.net Discussion19/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in xhawk.net discussion 2.0 beta2 allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in a BBCode img tag.
ModificadaAlta (7.5)1.3%—Xhawk.net Discussion19/3/200616/6/2026
SQL injection vulnerability in discussion.class.php in xhawk.net discussion 2.0 beta2 allows remote attackers to execute arbitrary SQL commands via the view parameter.
ModificadaMedia (5)2.8%—Eschew.net Phpbannerexchange14/3/200616/6/2026
Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot dot) in the email parameter during a "Recover password" operation (recoverpw.php).
ModificadaMedia (5)1.2%—Zbattle.net Zbattle Client1/2/200616/6/2026
zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game.
ModificadaAlta (7.5)1.8%—Aspthai.net Aspthai Forums1/2/200616/6/2026
Vulnerabilidad de inyección SQL en login.asp en ASPThai.Net ASPThai Forums 8.0 y versiones anteriores permiten a atacantes remotos ejecutar comandos SQL arbitrarios y eludir la autenticación de inicio de sesión a través del campo de contraseña.
ModificadaMedia (5)1.6%—Theworldsend.net Php-ping31/1/200616/6/2026
PHP-Ping 1.3 does not properly validate ping counts, which allows remote attackers to cause a denial of service (ping flood) via a negative count parameter.
ModificadaMedia (4.3)1.4%—Freekrai.net MY Amazon Store Manager21/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some sources claim that the affected parameter is "q", but the only public archive of the original researcher notification shows an XSS…
ModificadaMedia (5.8)1.5%—8pixel.net Simple Blog18/1/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts.