Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

86 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.1%—I-escorts Agency ScriptI-escorts Directory Script11/5/201016/6/2026
Multiple SQL injection vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party…
ModificadaMedia (4.3)1.2%💥 ExploitI-escorts Agency ScriptI-escorts Directory Script11/5/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to inject arbitrary web script or HTML via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%—Boldfx Model Agency Manager PRO18/3/201016/6/2026
SQL injection vulnerability in photos.php in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allows remote attackers to execute arbitrary SQL commands via the album parameter.
ModificadaMedia (4.3)1.6%💥 ExploitDatetopia Match Agency BIZ24/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) important parameter to edit_profile.php and (2) pid parameter to report.php.
ModificadaAlta (7.5)0.92%💥 ExploitBoldfx Model Agency Manager PRO11/9/200916/6/2026
Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php; and the (4) id parameter to forum_message.php.
ModificadaMedia (6.4)2.8%💥 ExploitAgency4net Webftp4/1/200816/6/2026
Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the file parameter.
ModificadaMedia (6.8)2.7%💥 ExploitF-art Agency Blog CMS22/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in list.php in BLOG:CMS 4.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the FADDR parameter.
ModificadaAlta (7.5)2.6%—F-art Agency Blog CMS13/9/200616/6/2026
Multiple SQL injection vulnerabilities in F-ART BLOG:CMS 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) xagent, (2) xpath, (3) xreferer, and (4) xdns parameters in (a) admin/plugins/NP_Log.php, and the (5) pitem parameter in (b) admin/plugins/NP_Poll.php; and allow remote authenticated users…
ModificadaAlta (7.5)2.1%💥 ExploitF-art Agency Blog CMS6/7/200616/6/2026
SQL injection vulnerability in index.php in the NP_SEO plugin in BLOG:CMS before 4.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5)1.4%—F-art Agency Blog CMSPunbb31/12/200516/6/2026
PunBB 1.2.9, used alone or with F-ART BLOG:CMS, may trust a client's IP address as specified in the X-Forwarded-For HTTP header rather than the TCP/IP stack, which allows remote attackers to misrepresent their IP address by sending a modified header.
ModificadaAlta (10)1.9%—Recruitment Agency Software Online Recruitment Agency31/12/200416/6/2026
Multiple unknown vulnerabilities in Online Recruitment Agency 1.0 have unknown impact and attack vectors.