Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

152 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.00%💥 ExploitJoomla COM Shambo2Mambo COM Shambo2Phil Taylor Shambo26/2/200816/6/2026
SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.
ModificadaAlta (7.5)1.1%💥 ExploitMamboserver JoomlaMamboserver Mambo4/2/200816/6/2026
SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
ModificadaAlta (7.5)1.1%💥 ExploitArthur Konze Webdesign AkogalleryJoomlaMambo4/2/200816/6/2026
SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
ModificadaAlta (7.5)1.1%💥 ExploitMamboserver Catalogshop4/2/200816/6/2026
SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
ModificadaAlta (7.5)1.0%💥 ExploitDarko Selesi EstateagentJoomlaMambo31/1/200816/6/2026
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.
ModificadaAlta (7.5)1.0%💥 ExploitJoomla COM JokesMambo COM Jokes31/1/200816/6/2026
SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a CatView action.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla GlossaryMambo Glossary31/1/200816/6/2026
SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla Musepoes ComponentMambo Musepoes Component31/1/200816/6/2026
SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.
ModificadaAlta (7.5)0.99%💥 ExploitJoomla COM MammlMambo COM Mamml31/1/200816/6/2026
SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
ModificadaAlta (7.5)1.0%💥 ExploitJoomla COM RecipesMambo COM Recipes31/1/200816/6/2026
SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM NewsletterMambo COM NewsletterMambo31/1/200816/6/2026
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
ModificadaAlta (10)1.5%—Mamboxchange Laithai30/1/200816/6/2026
Multiple unspecified vulnerabilities in Mambo LaiThai 4.5.5 have unknown impact and attack vectors related to (1) mod_login and (2) mod_template_chooser.
ModificadaAlta (7.5)1.1%—Mamboxchange Laithai30/1/200816/6/2026
SQL injection vulnerability in Mambo LaiThai 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5)1.4%—Mambo Open Source15/1/200816/6/2026
Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.
ModificadaMedia (4.3)1.5%💥 ExploitMambo20/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com_frontpage option and the (2) option parameter.
ModificadaMedia (6.8)37%💥 ExploitAg-solutions Mosmedia LiteJoomlaMambo11/10/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2) info.html.php, (3) media.divs.php, (4)…
ModificadaAlta (7.5)0.99%💥 ExploitMambadsMambo3/10/200716/6/2026
SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter.
ModificadaMedia (4.3)1.3%—Joomla AkobookMambo Site Server6/9/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook 3.42 and earlier component (com_akobook) for Mambo allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) gbmail and (2) gbpage parameters in the sign function.
ModificadaAlta (7.5)1.0%💥 ExploitMambo RemositoryMamboserver Mambo23/8/200716/6/2026
SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.
ModificadaAlta (7.5)2.4%💥 ExploitMamboParkview Consultants Simplefaq21/8/200716/6/2026
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.
ModificadaAlta (9.3)1.9%—Mambo Open Source8/8/200716/6/2026
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
ModificadaMedia (4)0.85%—Mambo9/5/200716/6/2026
MOStlyDB Admin in Mambo 4.6.1 does not properly check privileges, which allows remote authenticated administrators to have an unknown impact via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.8)1.4%—Mambo Open Source9/5/200716/6/2026
The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read certain content via unspecified vectors.
ModificadaAlta (7.5)8.0%💥 ExploitMinibbTosmo Mambo26/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3)…
ModificadaMedia (6.8)1.7%—Joomla JambookMambo Jambook24/4/200716/6/2026
PHP remote file inclusion vulnerability in jambook.php in the Jambook (com_Jambook) 1.0 beta7 module for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by a reliable third party because the jambook.php…
Orbitaley — Vulnerabilidades