Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Php-fusion THE Kroax Module | 21/11/2008 | 16/6/2026 | SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Php-fusion Freshlinks Module | 14/11/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Freshlinks 1.0 RC1 module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the linkid parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Php-fusion Recepies Module | 9/10/2008 | 16/6/2026 | SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the kat_id parameter in a kategorier action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Php-fusion World OF Warcraft Tracker Infusion Module | 9/10/2008 | 16/6/2026 | SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Php-fusion Forum Rank System | 14/5/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the settings[locale] parameter to (1) forum.php and (2) profile.php in infusions/rank_system/. NOTE: the provenance of this information is unknown;… | |
| Modificada | Media (6) | 1.5% | 💥 Exploit | Php-fusion | 23/4/2008 | 16/6/2026 | SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the database table prefix is known, allows remote authenticated users to execute arbitrary SQL commands via the submit_info[] parameter in a link submission action. NOTE: it was later reported that… | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Php-fusion Expanded Calendar Module | 3/10/2007 | 16/6/2026 | SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the sel parameter. | |
| Modificada | Baja (3.5) | 0.87% | — | Php-fusion | 4/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in infusions/shoutbox_panel/shoutbox_panel.php in PHP-Fusion 6.01.10 and 6.01.9, when guest posts are enabled, allows remote authenticated users to inject arbitrary web script or HTML via the URI, related to the FUSION_QUERY constant. | |
| Modificada | Media (5) | 1.5% | — | Php-fusionAI | 22/11/2005 | 16/6/2026 | Unspecified vulnerability in subheader.php in PHP-Fusion 6.00.206 and earlier allows remote attackers to obtain the full path via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Php-fusionAI | 6/10/2005 | 16/6/2026 | SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158. |