Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.1% | — | I-escorts Agency ScriptI-escorts Directory Script | 11/5/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | I-escorts Agency ScriptI-escorts Directory Script | 11/5/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to inject arbitrary web script or HTML via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Boldfx Model Agency Manager PRO | 18/3/2010 | 16/6/2026 | SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Datetopia Match Agency BIZ | 24/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php. | |
| Modificada | Alta (7.5) | 0.92% | 💥 Exploit | Boldfx Model Agency Manager PRO | 11/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php; and the (4) id parameter to forum_message.php. | |
| Modificada | Media (6.4) | 2.8% | 💥 Exploit | Agency4net Webftp | 4/1/2008 | 16/6/2026 | Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (6.8) | 2.7% | 💥 Exploit | F-art Agency Blog CMS | 22/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in list.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the FADDR parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | F-art Agency Blog CMS | 13/9/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in F-ART BLOG:CMS 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) xagent, (2) xpath, (3) xreferer, and (4) xdns parameters in (a) admin/plugins/NP_Log.php, and the (5) pitem parameter in (b) admin/plugins/NP_Poll.php; and allow remote authenticated users… | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | F-art Agency Blog CMS | 6/7/2006 | 16/6/2026 | SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 1.4% | — | F-art Agency Blog CMSPunbb | 31/12/2005 | 16/6/2026 | PunBB 1.2.9, used alone or with F-ART BLOG:CMS, may trust a client's IP address as specified in the X-Forwarded-For HTTP header rather than the TCP/IP stack, which allows remote attackers to misrepresent their IP address by sending a modified header. | |
| Modificada | Alta (10) | 1.9% | — | Recruitment Agency Software Online Recruitment Agency | 31/12/2004 | 16/6/2026 | Multiple unknown vulnerabilities in Online Recruitment Agency 1.0 have unknown impact and attack vectors. |