Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.3% | 💥 Exploit | Phpstore Complete Classifieds | 11/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in classifieds1/yellow_images/. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Radscripts Radclassifieds | 27/7/2009 | 16/6/2026 | SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Almondsoft Almond Classifieds | 22/7/2009 | 16/6/2026 | SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Virtuenetz Virtue Classifieds | 9/6/2009 | 16/6/2026 | SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Openautoclassifieds Open Auto Classifieds | 7/4/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Comscripts Quick Classifieds | 30/3/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) locate.php3, (3) search_results.php3, (4) classifieds/index.php3, and (5) classifieds/view.php3; (6) index.php3, (7) manager.php3, (8) pass.php3, (9) remember.php3 (10)… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Bosdev BOS Classifieds | 25/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Turnkeyforms Local Classifieds | 2/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Turnkeyforms Local Classifieds | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Softbizscripts Classifieds Script | 27/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio parameter to gallery.php, (4) msg parameter to lostpassword.php,… | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Softbizscripts Classifieds Script | 26/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Turnkeyforms Local Classifieds | 26/2/2009 | 16/6/2026 | TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | WEB Scribble Solutions Webclassifieds | 2/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Web Scribble Solutions webClassifieds 2005 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) password fields in a sign_in action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Deltascripts PHP Classifieds | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Deltascripts PHP Classifieds | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Yourfreeworld Classifieds Blaster Script | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Yourfreeworld Classifieds Hosting Script | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Spice Classifieds | 11/9/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands via the cat_path parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Yourfreeworld Classifieds | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mojoscripts Mojoclassifieds | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mybizz-classifieds | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Carscripts Classifieds | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Boatscripts Classifieds | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL commands via the type parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Phpclassifiedsscript PHP Classifieds Script | 27/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | 68 Classifieds | 19/5/2008 | 16/6/2026 | SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter. |