Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.93%—Esoftpro Online Guestbook PRO13/7/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display parameter.
ModificadaMedia (4.3)1.5%💥 ExploitEsoftpro Online Guestbook PRO13/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter.
ModificadaMedia (4.3)1.7%💥 ExploitJnmsolutions Guestbook13/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModificadaMedia (6.8)2.2%💥 ExploitW3bcms Gaestebuch Guestbook Module7/7/200916/6/2026
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the spam_id parameter.
ModificadaAlta (7.5)0.93%💥 ExploitMaxdev Cwguestbook2/7/200916/6/2026
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attackers to execute arbitrary SQL commands via the rid parameter in a viewrecords action to modules.php.
ModificadaMedia (4.3)1.4%—AN Guestbook26/6/200916/6/2026
Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter.
ModificadaMedia (5)2.6%💥 ExploitWebwizguide WEB WIZ Guestbook2/4/200916/6/2026
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected.
ModificadaMedia (5)2.4%💥 ExploitJAX Scripts JAX Guestbook31/3/200916/6/2026
Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.
ModificadaMedia (4.3)1.5%💥 ExploitJAX Scripts JAX Guestbook31/3/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is…
ModificadaAlta (7.5)0.97%💥 ExploitXatrix Xguestbook4/3/200916/6/2026
SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.
ModificadaAlta (7.5)1.2%—Chipmunk Scripts Chipmunk Guestbook2/3/200916/6/2026
SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter.
ModificadaMedia (4.3)1.7%—Phpf1 Max's Guestbook2/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message parameters.
ModificadaMedia (5)2.3%💥 ExploitMinitdesign Virtual Guestbook10/2/200916/6/2026
Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.
ModificadaMedia (4.3)1.1%—AN Guestbook5/2/200916/6/2026
Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from…
ModificadaMedia (5)2.6%💥 ExploitEmefa Guestbook6/1/200916/6/2026
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.
ModificadaMedia (4.3)1.8%💥 ExploitEpistream Ipei Guestbook27/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the pg parameter, a different vector than CVE-2005-4597.
ModificadaMedia (4.3)1.0%—Aguestbook AN Guestbook27/8/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook (ANG) before 0.7.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)6.5%💥 ExploitMaian Guestbook25/7/200816/6/2026
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie.
ModificadaMedia (4.3)1.4%💥 ExploitAguestbook AN Guestbook22/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in send_email.php in AN Guestbook (ANG) 0.4 allows remote attackers to inject arbitrary web script or HTML via the postid parameter.
ModificadaMedia (4.3)1.1%—Maianscriptworld Maian Guestbook14/5/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in admin/inc/footer.php in Maian Guestbook 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg_script2 and (2) msg_script3 parameters.
ModificadaAlta (7.5)1.5%—Savas Place Savas Guestbook2/4/200816/6/2026
Directory traversal vulnerability in index.php in Sava's GuestBook 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4)3.1%—Dmsguestbook Project Dmsguestbook6/2/200816/6/2026
Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.
ModificadaMedia (4.3)2.3%—Dmsguestbook Project Dmsguestbook6/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea.
ModificadaMedia (6.5)4.3%💥 ExploitDmsguestbook Project Dmsguestbook6/2/200816/6/2026
SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
ModificadaMedia (4.3)1.5%—Dmsguestbook Project Dmsguestbook6/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown;…
Orbitaley — Vulnerabilidades