Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Article System | 6/11/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en volume.php en Article System 0.6 permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro config[public_dir]. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Article Script | 6/11/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en rss.php en Article Script 1.6.3 y anteriores permite a atacantes remotos ejecutar comandos SQL mediante el parámetro category. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Articlebeach Script | 27/10/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en index.php en ArticleBeach Script 2.0 y anteriores permite a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro page. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Techno Dreams Articles AND Papers Package | 19/9/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en ArticlesTableview.asp en Techno Dreams Articles & Papers Package 2.0 y anteriores permite a atacantes remotos ejecutar comandos SQL de su elección vía el parámetro key. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Spoonlabs Vivvo Article Management CMS | 12/9/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en pdf_version.php en SpoonLabs Vivvo Article Management CMS (también conocido como phpWordPress) 3.2 y anteriores, permitea un atacante remoto ejecutar comandos SQL a través del parámetro id. | |
| Modificada | Media (5.1) | 3.4% | 💥 Exploit | Spoonlabs Vivvo Article Management CMS | 12/9/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en index.php en SpoonLabs Vivvo Article Management CMS (también conocido como phpWordPress) 3.2 y anteriores, cuando register_globals es habilitado, permite a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro classified_path. | |
| Modificada | Media (4.3) | 1.9% | — | Okscripts Okarticles | 13/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in OkScripts OkArticles 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (4.3) | 2.2% | — | Particle Soft Particle Wiki | 12/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Particle Soft Particle Wiki 1.0.2 allows remote attackers to inject arbitrary web script or HTML via a BR element with an extraneous IMG tag and a STYLE attribute that contains "/**/" comment sequences, which bypasses the XSS protection scheme. | |
| Modificada | Media (4.3) | 1.8% | — | Particle Soft Particle Whois | 12/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Particle Soft Particle Whois 1.0.3 allow remote attackers to inject arbitrary web script or HTML via (1) the target parameter in index.php and (2) the "input box." | |
| Modificada | Media (5) | 1.4% | — | Particle Soft Particle Links | 8/6/2006 | 16/6/2026 | Partial Links 1.2.2 allows remote attackers to obtain sensitive information via a direct request to (1) page_footer.php and (2) page_header.php, which displays the path in an error message. | |
| Modificada | Media (5) | 1.5% | — | Particle Soft Particle Links | 8/6/2006 | 16/6/2026 | Directory traversal vulnerability in Particle Links 1.2.2 might allow remote attackers to access arbitrary files via ".." sequences in an HTTP request. NOTE: it is not clear whether this issue is legitimate, as the original researcher seems unsure. | |
| Modificada | Baja (2.6) | 1.8% | — | Particle Soft Particle Links | 8/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.php in Particle Links 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Particle Soft Particle Links | 8/6/2006 | 16/6/2026 | SQL injection vulnerability in index.php in Partial Links 1.2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Particle Soft Particle Wiki | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in index.php in Particle Wiki 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Particle Soft Particle Gallery | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the imageid parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Alstrasoft Article Manager PRO | 24/5/2006 | 16/6/2026 | SQL injection vulnerability in Alstrasoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via (1) the author_id parameter in profile.php and (2) the aut_id parameter in userarticles.php. NOTE: the aut_id vector can produce resultant path disclosure if the SQL manipulation is invalid. | |
| Modificada | Media (4.3) | 1.2% | — | Alstrasoft Article Manager PRO | 24/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in submit_article.php in Alstrasoft Article Manager Pro 1.6 allows remote attackers to inject arbitrary web script or HTML when submitting an article, as demonstrated using a javascript URI in a Cascading Style Sheets (CSS) property of a STYLE attribute of an element. | |
| Modificada | Media (5) | 1.4% | — | Alstrasoft Article Manager PRO | 24/5/2006 | 16/6/2026 | Alstrasoft Article Manager Pro 1.6 allows remote attackers to obtain sensitive information via (1) a quote character or possibly an invalid value in the action parameter in a request to mrarticles.php or (2) a login QUERY_STRING to admin.php without any additional parameters, which reveal the path in various error… | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Smartisoft Phpbazar | 22/5/2006 | 16/6/2026 | Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Smartisoft Phplistpro | 22/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the Language cookie. | |
| Modificada | Media (6.4) | 3.0% | 💥 Exploit | Smartisoft Phpbazar | 22/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter. | |
| Modificada | Media (5.1) | 9.8% | 💥 Exploit | Smartisoft Phplistpro | 12/5/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config.php vector is already covered by CVE-2006-1749. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Scriptsfrenzy Article Publisher PRO | 19/4/2006 | 16/6/2026 | SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Smartisoft Phplistpro | 12/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in phpListPro 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the returnpath parameter. NOTE: this issue was later reported to affect 2.01 as well. | |
| Modificada | Alta (7.5) | 1.8% | — | Articlesone 99articles Directory | 22/3/2006 | 16/6/2026 | PHP remote file include vulnerability in index.php in 99Articles.com (aka ArticlesOne.com) Free articles directory allows remote attackers to include and execute arbitrary PHP code via a URL in the page parameter. |