Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
152 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Mambo Calendar | 16/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php. | |
| Modificada | Media (6.8) | 6.7% | 💥 Exploit | Joomla Taskhopper ComponentMambo Taskhopper Component | 12/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) contact_type.php, (2) itemstatus_type.php, (3) projectstatus_type.php, (4) request_type.php, (5)… | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Mamboxchange COM Zoom | 12/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) EXIF_Makernote.php or (2) EXIF.php in classes/iptc/. | |
| Modificada | Media (6.8) | 5.0% | 💥 Exploit | Mambo Flatmenu | 27/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Joomla Swmenu ComponentMambo Swmenu Component | 27/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2)… | |
| Modificada | Alta (9.3) | 7.8% | 💥 Exploit | Joomla NFN Address BookMambo NFN Address Book | 22/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) components/com_nfn_addressbook/nfnaddressbook.php or (2)… | |
| Modificada | Alta (7.5) | 1.2% | — | Mambo Open Source | 7/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) com_comment.php. | |
| Modificada | Media (4.3) | 1.2% | — | Mambo | 7/3/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from mod_login.php; and the (2) mcname parameter to (b) moscomment.php and (c) com_comment.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Mambo Mostlyce | 3/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Mamboxchange Laithai | 2/3/2007 | 16/6/2026 | SQL injection vulnerability in includes/mambo.php in Mambo LaiThai 4.5.4 SP2 and earlier allows remote attackers to execute arbitrary SQL commands via the usercookie[password] cookie parameter. | |
| Modificada | Media (5.8) | 1.1% | — | Mamboxchange Laithai | 2/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mambo LaiThai 4.5.4 Security Patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.1% | — | Mambo | 6/2/2007 | 16/6/2026 | SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | JoomlaMambo | 19/1/2007 | 16/6/2026 | SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Mambo Extcalthai Module | 18/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIG_EXT[LANGUAGES_DIR] parameter to admin_events.php, (2) the mosConfig_absolute_path parameter to extcalendar.php,… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Mamboxchange Mosreporter | 22/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Mamboxchange Extended Registration | 12/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Joomla Prince Clan Chess ComponentMambo Prince Clan Chess Component | 27/9/2006 | 16/6/2026 | Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors. | |
| Modificada | Media (6.8) | 6.9% | 💥 Exploit | Mamboxchange Serverstat Component | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Joomla JIM ComponentMambo JIM Component | 6/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in the JIM component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: another researcher has stated that the product distribution does not include an index.php file. Also, this… | |
| Modificada | Media (6.8) | 5.0% | 💥 Exploit | Joomla COM Comprofiler ComponentMambo COM Comprofiler Component | 6/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Mambo Contacts XTD Component | 26/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in contxtd.class.php in the Contacts XTD (ContXTD) component for Mambo (com_contxtd) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: another researcher has disputed this issue, saying that the software prevents the… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Mambo Bigape-backup Component | 23/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include arbitrary files via the mosConfig_absolute_path parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Mambo | 22/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in contentpublisher.php in the contentpublisher component (com_contentpublisher) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: this issue has been disputed by third parties who state that… | |
| Modificada | Media (6.8) | 5.8% | 💥 Exploit | A6mambocredits Component | 22/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Mamboxchange Mambowiki | 22/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter. |