Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.98% | 💥 Exploit | Cplinks | 13/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) admin_username parameter (aka the username field) to admin/index.php and the (2) search_text and (3) search_category parameters to search.php. NOTE: some of… | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Cplinks | 13/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in search.php in cpLinks 1.03 allow remote attackers to inject arbitrary web script or HTML via the (1) search_text and (2) search_category parameters. NOTE: the XSS reportedly occurs in a forced SQL error message. NOTE: some of these details are obtained from third… | |
| Modificada | Media (6.8) | 0.97% | 💥 Exploit | Cplinks Cpdynalinks | 12/10/2007 | 16/6/2026 | SQL injection vulnerability in category.php in cpDynaLinks 1.02 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Grouplink Ehelpdesk | 3/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in GroupLink eHelpDesk 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) NA_DISPLAYNAME parameter in helpdesk/user/rf_create.jsp and the (2) username and (3) LDAPError parameters in index2.jsp. NOTE: the provenance of this information is… | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | David Watters Helplink | 26/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Idevspot Phplinkexchange | 13/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in bits_listings.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary code via the svr_rootPhpStart parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Idevspot Phplinkexchange | 13/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Idevspot Phplinkexchange | 24/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Phplinks | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter. | |
| Modificada | Media (5) | 1.2% | — | Greg Donald Phplinks | 31/12/2004 | 16/6/2026 | index.php in PHP Links allows remote attackers to gain sensitive information via an invalid show parameter, which reveals the full path in an error message. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Phplinkat | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote attackers to inject arbitrary web script or HTML via the catid parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Myphpsoft Myphplinks | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the idsession parameter. |