Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

804 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.2%💥 ExploitArticle System6/11/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en volume.php en Article System 0.6 permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro config[public_dir].
ModificadaAlta (7.5)1.3%💥 ExploitArticle Script6/11/200616/6/2026
Vulnerabilidad de inyección SQL en rss.php en Article Script 1.6.3 y anteriores permite a atacantes remotos ejecutar comandos SQL mediante el parámetro category.
ModificadaAlta (7.5)3.4%💥 ExploitArticlebeach Script27/10/200616/6/2026
Vulnerabilidad PHP de inclusión remota de archivo en index.php en ArticleBeach Script 2.0 y anteriores permite a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro page.
ModificadaAlta (7.5)2.6%💥 ExploitTechno Dreams Articles AND Papers Package19/9/200616/6/2026
Vulnerabilidad de inyección SQL en ArticlesTableview.asp en Techno Dreams Articles & Papers Package 2.0 y anteriores permite a atacantes remotos ejecutar comandos SQL de su elección vía el parámetro key.
ModificadaAlta (7.5)2.6%💥 ExploitSpoonlabs Vivvo Article Management CMS12/9/200616/6/2026
Vulnerabilidad de inyección SQL en pdf_version.php en SpoonLabs Vivvo Article Management CMS (también conocido como phpWordPress) 3.2 y anteriores, permitea un atacante remoto ejecutar comandos SQL a través del parámetro id.
ModificadaMedia (5.1)3.4%💥 ExploitSpoonlabs Vivvo Article Management CMS12/9/200616/6/2026
Vulnerabilidad PHP de inclusión remota de archivo en index.php en SpoonLabs Vivvo Article Management CMS (también conocido como phpWordPress) 3.2 y anteriores, cuando register_globals es habilitado, permite a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro classified_path.
ModificadaMedia (4.3)1.9%—Okscripts Okarticles13/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
ModificadaMedia (4.3)2.2%—Particle Soft Particle Wiki12/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Particle Soft Particle Wiki 1.0.2 allows remote attackers to inject arbitrary web script or HTML via a BR element with an extraneous IMG tag and a STYLE attribute that contains "/**/" comment sequences, which bypasses the XSS protection scheme.
ModificadaMedia (4.3)1.8%—Particle Soft Particle Whois12/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box."
ModificadaMedia (5)1.4%—Particle Soft Particle Links8/6/200616/6/2026
Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message.
ModificadaMedia (5)1.5%—Particle Soft Particle Links8/6/200616/6/2026
Directory traversal vulnerability in Particle Links 1.2.2 might allow remote attackers to access arbitrary files via ".." sequences in an HTTP request. NOTE: it is not clear whether this issue is legitimate, as the original researcher seems unsure.
ModificadaBaja (2.6)1.8%—Particle Soft Particle Links8/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in admin.php in Particle Links 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaAlta (7.5)1.2%—Particle Soft Particle Links8/6/200616/6/2026
SQL injection vulnerability in index.php in Partial Links 1.2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.
ModificadaAlta (7.5)1.2%💥 ExploitParticle Soft Particle Wiki6/6/200616/6/2026
SQL injection vulnerability in index.php in Particle Wiki 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.
ModificadaAlta (7.5)1.2%—Particle Soft Particle Gallery6/6/200616/6/2026
SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the imageid parameter.
ModificadaAlta (7.5)1.3%—Alstrasoft Article Manager PRO24/5/200616/6/2026
SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the author_id parameter in profile.php and (2) the aut_id parameter in userarticles.php. NOTE: the aut_id vector can produce resultant path disclosure if the SQL manipulation is invalid.
ModificadaMedia (4.3)1.2%—Alstrasoft Article Manager PRO24/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in submit_article.php in Alstrasoft Article Manager Pro 1.6 allows remote attackers to inject arbitrary web script or HTML when submitting an article, as demonstrated using a javascript URI in a Cascading Style Sheets (CSS) property of a STYLE attribute of an element.
ModificadaMedia (5)1.4%—Alstrasoft Article Manager PRO24/5/200616/6/2026
Alstrasoft Article Manager Pro 1.6 allows remote attackers to obtain sensitive information via (1) a quote character or possibly an invalid value in the action parameter in a request to mrarticles.php or (2) a login QUERY_STRING to admin.php without any additional parameters, which reveal the path in various error…
ModificadaAlta (7.5)3.3%💥 ExploitSmartisoft Phpbazar22/5/200616/6/2026
Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1.
ModificadaAlta (7.5)3.0%💥 ExploitSmartisoft Phplistpro22/5/200616/6/2026
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the Language cookie.
ModificadaMedia (6.4)3.0%💥 ExploitSmartisoft Phpbazar22/5/200616/6/2026
PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.
ModificadaMedia (5.1)9.8%💥 ExploitSmartisoft Phplistpro12/5/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config.php vector is already covered by CVE-2006-1749.
ModificadaAlta (7.5)1.1%💥 ExploitScriptsfrenzy Article Publisher PRO19/4/200616/6/2026
SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter.
ModificadaAlta (7.5)8.1%💥 ExploitSmartisoft Phplistpro12/4/200616/6/2026
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter. NOTE: this issue was later reported to affect 2.01 as well.
ModificadaAlta (7.5)1.8%—Articlesone 99articles Directory22/3/200616/6/2026
PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the page parameter.