Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.93% | — | Esoftpro Online Guestbook PRO | 13/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Esoftpro Online Guestbook PRO | 13/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Jnmsolutions Guestbook | 13/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | W3bcms Gaestebuch Guestbook Module | 7/7/2009 | 16/6/2026 | SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Maxdev Cwguestbook | 2/7/2009 | 16/6/2026 | SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php. | |
| Modificada | Media (4.3) | 1.4% | — | AN Guestbook | 26/6/2009 | 16/6/2026 | Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Webwizguide WEB WIZ Guestbook | 2/4/2009 | 16/6/2026 | Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | JAX Scripts JAX Guestbook | 31/3/2009 | 16/6/2026 | Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | JAX Scripts JAX Guestbook | 31/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Xatrix Xguestbook | 4/3/2009 | 16/6/2026 | SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Chipmunk Scripts Chipmunk Guestbook | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Phpf1 Max's Guestbook | 2/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Minitdesign Virtual Guestbook | 10/2/2009 | 16/6/2026 | Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb. | |
| Modificada | Media (4.3) | 1.1% | — | AN Guestbook | 5/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from… | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Emefa Guestbook | 6/1/2009 | 16/6/2026 | Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Epistream Ipei Guestbook | 27/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg parameter, a different vector than CVE-2005-4597. | |
| Modificada | Media (4.3) | 1.0% | — | Aguestbook AN Guestbook | 27/8/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook (ANG) before 0.7.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 6.5% | 💥 Exploit | Maian Guestbook | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Aguestbook AN Guestbook | 22/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Guestbook | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Guestbook 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script2 and (2) msg_script3 parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Savas Place Savas Guestbook | 2/4/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in Sava's GuestBook 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4) | 3.1% | — | Dmsguestbook Project Dmsguestbook | 6/2/2008 | 16/6/2026 | Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters. | |
| Modificada | Media (4.3) | 2.3% | — | Dmsguestbook Project Dmsguestbook | 6/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea. | |
| Modificada | Media (6.5) | 4.3% | 💥 Exploit | Dmsguestbook Project Dmsguestbook | 6/2/2008 | 16/6/2026 | SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries. | |
| Modificada | Media (4.3) | 1.5% | — | Dmsguestbook Project Dmsguestbook | 6/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown;… |