Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.5% | 💥 Exploit | Grayscalecms Bandsite CMS | 24/8/2009 | 16/6/2026 | BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a direct request. | |
| Modificada | Media (5) | 1.0% | — | Phpadultsite CMS | 19/8/2009 | 16/6/2026 | index.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to obtain the full installation path via an invalid results_per_page parameter, which leaks the path in an error message. NOTE: this issue might be resultant from a separate SQL injection vulnerability. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpadultsite CMS | 19/8/2009 | 16/6/2026 | SQL injection vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to execute arbitrary SQL commands via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.0% | 💥 Exploit | Phpadultsite CMS | 19/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue might be resultant… | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | 4site CMS | 18/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i parameters to portfolio/index.shtml, (6) h parameter to hotel/index.php,… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Bandsitecms Bandsite CMS | 12/12/2008 | 16/6/2026 | BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Foresite CMS | 1/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (5) | 1.5% | — | Grayscale Bandsite CMS | 26/9/2006 | 16/6/2026 | Grayscale BandSite CMS allows remote attackers to obtain sensitive information via a direct request for (1) certain files in the includes/content directory, (2) includes/shows_preview.php, and (3) adminpanel/configform.php; and files in adminpanel/includes/ including (4) mailinglist/disphtmltbl.php, (5)… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Grayscale Bandsite CMS | 26/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Grayscale BandSite CMS allow remote attackers to inject arbitrary web script or HTML via (1) the max_file_size_purdy parameter in adminpanel/includes/helpfiles/help_mp3.php, (2) the message_text parameter in adminpanel/includes/mailinglist/sendemail.php, (3) the… | |
| Modificada | Alta (7.5) | 1.6% | — | Grayscale Bandsite CMS | 26/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter in (1) adminpanel/includes/mailinglist/mlist_xls.php and (2) adminpanel/includes/add_forms/addmp3.php. NOTE: the other vectors from the… | |
| Modificada | Media (5.1) | 15% | 💥 Exploit | Grayscale Bandsite CMS | 23/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php; multiple files in adminpanel/includes/add_forms/ including (2)… |