Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 2.6% | — | Awpcp Another Wordpress Classifieds Plugin | 6/9/2012 | 16/6/2026 | Unspecified vulnerability in the Another WordPress Classifieds Plugin before 2.0 for WordPress has unknown impact and attack vectors related to "image uploads." | |
| Modificada | Baja (3.5) | 0.93% | 💥 Exploit | Dclassifieds | 7/2/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Deltascripts PHP Classifieds | 8/10/2011 | 16/6/2026 | PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Sellatsite PHP Classifieds ADS | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter. | |
| Modificada | Media (5) | 1.3% | — | Kamads Classifieds 2 B3 | 23/9/2011 | 16/6/2026 | Kamads Classifieds 2_B3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by V2A_XHTML/style/view.php and certain other files. | |
| Modificada | Media (4.3) | 1.1% | — | Open-classifieds Open Classifieds | 16/9/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Open Classifieds 1.7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) desc, (2) price, (3) title, and (4) place parameters to index.php and the (5) subject parameter to contact.htm, related to content/contact.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Site2nite Boat Classifieds | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in detail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Site2nite Boat Classifieds | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the Id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Clscript Classifieds Script | 3/5/2010 | 16/6/2026 | SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitrary SQL commands via the hpId parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tukanas Easyclassifieds Script | 15/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Tukanas Classifieds (aka EasyClassifieds) Script 1.0 allows remote attackers to execute arbitrary SQL commands via the b parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Yourfreeworld Ultra Classifieds PRO | 2/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in listads.php in YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject arbitrary web script or HTML via the cn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Yourfreeworld Ultra Classifieds PRO | 2/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php. | |
| Modificada | Media (4.3) | 1.1% | — | Almondsoft Affiliate Network ClassifiedsAlmondsoft Almond Classifieds | 16/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to inject arbitrary web script or HTML via the city parameter in a search action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Almondsoft Affiliate Network ClassifiedsAlmondsoft Almond Classifieds | 16/9/2009 | 16/6/2026 | SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Almondsoft Almond Classifieds | 16/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse action to index.php or (2) the addr parameter to gmap.php. NOTE: some… | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Phpclassifiedsscript PHP Classifieds Script | 25/8/2009 | 16/6/2026 | Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Ajsquare AJ Classifieds | 24/8/2009 | 16/6/2026 | AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php. | |
| Modificada | Media (4.3) | 0.85% | — | Xzeroscripts Xzero Community Classifieds | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.85% | — | Xzeroscripts Xzero Community Classifieds | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Xzeroscripts Xzero Community Classifieds | 20/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Classifiedphpscript PHP Open Classifieds Script | 17/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | 68 Classifieds | 17/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (4) searchresults.php and (5) toplistings.php, and (6) member… | |
| Modificada | Media (6.5) | 4.0% | 💥 Exploit | Scriptsfeed Auto Classifieds | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/. | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Scriptsfeed Realtor Classifieds System | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/. | |
| Modificada | Media (6.5) | 3.4% | 💥 Exploit | Phpstore Auto Classifieds | 11/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in cars/cars_images/. |