Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.69% | — | Mojoportal | 24/2/2018 | 17/6/2026 | mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be… | |
| Modificada | Media (4.8) | 0.82% | — | Mojoportal | 2/1/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content… | |
| Modificada | Media (4.3) | 2.1% | — | Sourcetreesolutions Mojoportal | 20/8/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Forums/EditPost.aspx in mojoPortal before 2.3.9.8 allows remote attackers to inject arbitrary web script or HTML via the txtSubject parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Mojolicious | 3/5/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the link_to helper in Mojolicious before 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 2.0% | — | Mojolicious | 3/5/2011 | 16/6/2026 | Mojolicious before 0.999927 does not properly implement HMAC-MD5 checksums, which has unspecified impact and remote attack vectors. | |
| Modificada | Alta (10) | 2.1% | — | Mojolicious | 3/5/2011 | 16/6/2026 | Commands.pm in Mojolicious before 0.999928 does not properly perform CGI environment detection, which has unspecified impact and remote attack vectors. | |
| Modificada | Alta (10) | 1.3% | — | Mojolicious | 3/5/2011 | 16/6/2026 | Unspecified vulnerability in the MojoX::Dispatcher::Static implementation in Mojolicious before 0.991250 has unknown impact and attack vectors. | |
| Modificada | Media (5) | 3.9% | — | Mojolicious | 29/4/2011 | 16/6/2026 | Directory traversal vulnerability in Path.pm in Mojolicious before 1.16 allows remote attackers to read arbitrary files via a %2f..%2f (encoded slash dot dot slash) in a URI. | |
| Modificada | Media (6.8) | 2.5% | 💥 Exploit | Sourcetreesolutions Mojoportal | 24/9/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of administrators for requests that rename arbitrary files, as demonstrated by causing the user.config file to be moved, leading… | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Sourcetreesolutions Mojoportal | 24/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script or HTML via the User ID parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Mojoblog | 21/4/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) wp-comments-post.php and (2) wp-trackback.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mojoscripts Mojopersonals | 31/7/2008 | 16/6/2026 | SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mojoscripts Mojoclassifieds | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mojoscripts Mojoauto | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via the cat_a parameter in a browse action. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Mojoscripts Mojojobs | 24/7/2008 | 16/6/2026 | SQL injection vulnerability in mojoJobs.cgi in MojoJobs allows remote attackers to execute arbitrary SQL commands via the cat_a parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Mojoscripts Mojogallery | 14/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via "password input." | |
| Modificada | Media (4.3) | 1.2% | — | Mojoscripts Mojogallery | 11/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.cgi in mojoscripts.com mojoGallery allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Mojo Mail | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mojo.cgi for Mojo Mail 2.7 allows remote attackers to inject arbitrary web script via the email parameter. |