Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.8% | — | Zahmit Design Connections Business Directory Plugin | 16/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/admin/pages/manage.php in the Connections Business Directory plugin before 8.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s variable. | |
| Modificada | Media (5.4) | 0.27% | — | Ukbusinessaid Nigerias Business Directory | 19/10/2014 | 17/6/2026 | The Nigerias Business Directory (aka com.wNigeriasBusinessDirectory) application 0.70.13414.17619 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Wp-business Directory Project Wp-business Directory | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in forms/search.php in the WP-Business Directory (wp-ttisbdir) plugin 1.0.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) edit, (2) search_term, (3) page_id, (4) page, or (5) page_links parameter. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Myrephp Myre Business Directory | 25/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script or HTML via the look parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Myrephp Myre Business Directory | 25/8/2013 | 16/6/2026 | SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Brotherscripts Business Directory | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Scriptsfeed Business Directory Software | 24/3/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to execute arbitrary SQL commands via the (1) us and (2) ps parameters. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Activewebsoftwares Active Business Directory | 30/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Scripts-for-sites EZ Home Business Directory | 1/5/2009 | 16/6/2026 | SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Activewebsoftwares Active Business Directory | 27/1/2009 | 16/6/2026 | SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Pozscripts Business Directory Script | 12/12/2008 | 16/6/2026 | SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Baja (3.5) | 0.69% | — | Bosdev Bosmarket Business Directory System | 5/11/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in BosDev BosMarket Business Directory System allow remote authenticated users to inject arbitrary web script or HTML via (1) user info (account details) or (2) a post. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Enthrallweb Dragon Business Directory PRO | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in bus_details.asp in Dragon Business Directory - Pro (aka Dragon Internet Business Search Directory - Pro) 3.01.12 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. |