Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Pangramsoft Pointter PHP Content Management System | 22/12/2010 | 16/6/2026 | Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpfaber Content Management System | 22/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in module.php in PHPFABER CMS, possibly 1.3.36, allows remote attackers to inject arbitrary web script or HTML via the mod parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Webblizzard Content Management System | 11/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Mario Valdez Content Management System | 14/5/2008 | 16/6/2026 | Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cm_imgpath parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Exv2 Content Management System | 15/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965. | |
| Modificada | Alta (7.5) | 1.5% | — | KAI Content Management System | 18/4/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in Kai Content Management System (K-CMS) 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the current_theme parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Exv2 Content Management System | 11/4/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php. | |
| Modificada | Crítica (9.1) | 1.2% | — | Exv2 Content Management System | 11/4/2007 | 16/6/2026 | Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. | |
| Modificada | Alta (7.5) | 1.4% | — | Webblizzard Content Management System | 11/4/2007 | 16/6/2026 | Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. | |
| Modificada | Media (4.3) | 1.0% | — | Webblizzard Content Management System | 11/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Pathos Content Management System | 10/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Net-side.net NET Side Content Management System | 27/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbitrary PHP code via a URL in the cms parameter. | |
| Modificada | Crítica (9.8) | 13% | 💥 Exploit | Exv2 Content Management System | 2/3/2007 | 16/6/2026 | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable. | |
| Modificada | Media (4.3) | 4.7% | 💥 Exploit | Exv2 Content Management System | 2/3/2007 | 16/6/2026 | Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Bpg-infotech Content Management System | 26/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in an unspecified BPG-InfoTech Content Management System product allow remote attackers to execute arbitrary SQL commands via the (1) vjob parameter in publications_list.asp or (2) InfoID parameter in publication_view.asp. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Phpfaber Content Management System | 31/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE:… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Exv2 Content Management System | 27/9/2006 | 16/6/2026 | SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Inter Network Marketing AG G3 Content Management System | 7/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search module in Inter Network Marketing (INM) CMS G3 allows remote attackers to inject arbitrary web script or HTML via the search_string parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Goldstag Content Management System | 27/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote attackers to inject arbitrary web script or HTML via the text parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Icms Content Management Systems Icms | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. | |
| Modificada | Alta (7.5) | 1.1% | — | Icms Content Management Systems Icms | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter. | |
| Modificada | Media (5) | 1.5% | — | Icms Content Management Systems Icms | 16/11/2005 | 16/6/2026 | PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Express-web Content Management System | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to… | |
| Modificada | Alta (7.5) | 7.6% | 💥 Exploit | NX N X WEB Content Management System 2002 | 31/12/2003 | 16/6/2026 | The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php) scripts in N/X 2002 allow remote attackers to execute arbitrary PHP code via a c_path that references a URL on a remote web server that contains the code. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | NCM Content Management System | 2/7/2001 | 16/6/2026 | content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter. |