Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.3% | 💥 Exploit | Thenetguys Aspired2poll | 2/3/2009 | 16/6/2026 | The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing the username and password via a direct request to ASPired2poll.mdb. | |
| Modificada | Alta (7.5) | 1.5% | — | Interspire Shopping Cart | 3/2/2009 | 16/6/2026 | The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | THE NET Guys Aspired2blog | 21/1/2009 | 16/6/2026 | The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | THE NET Guys Aspired2blog | 21/1/2009 | 16/6/2026 | SQL injection vulnerability in admin/blog_comments.asp in The Net Guys ASPired2Blog allows remote attackers to execute arbitrary SQL commands via the BlogID parameter. | |
| Modificada | Media (5) | 6.3% | 💥 Exploit | Thenetguys Aspired2quote | 12/1/2009 | 16/6/2026 | The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/quote.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Interspire Activekb | 19/5/2008 | 16/6/2026 | Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts in /admin. | |
| Modificada | Media (4.3) | 1.0% | — | Interspire Shopping Cart | 29/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Interspire Shopping Cart 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | THE NET Guys Aspired2protect | 30/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.asp in ASPired2Protect allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.4) | 1.1% | — | Interspire Activekb | 12/10/2007 | 16/6/2026 | SQL injection vulnerability in admin/index.php in Interspire ActiveKB 1.5 allows remote attackers to execute arbitrary SQL commands via the questId parameter in a hideQuestion ToDo action. NOTE: the catId vector is already covered by CVE-2007-5131. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Interspire Activekb NX | 12/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ActiveKB NX 2.5.4 allow remote attackers to inject arbitrary web script or HTML via the page parameter to the default URI for some directories, as demonstrated by (1) ActiveKB/ and (2) default/categories/ActiveKB/. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Interspire Activekb NX | 27/9/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: it was separately reported that ActiveKB 1.5 is also affected. | |
| Modificada | Alta (7.5) | 1.1% | — | Interspire Articlelive NX | 3/8/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Interspire ArticleLive NX before 1.7.1.2 have unknown impact and attack vectors, possibly related to (1) AL_SANITIZE and (2) "Calling the constructor to make sure things are checked, safe mode, etc." | |
| Modificada | Media (6.8) | 8.0% | 💥 Exploit | Interspire Sendstudio | 22/2/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals and allow_fopenurl are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOTDIR parameter to (1) createemails.inc.php and (2) send_emails.inc.php in /admin/includes/. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | THE NET Guys Aspired2poll | 14/11/2006 | 16/6/2026 | SQL injection vulnerability in MoreInfo.asp in The Net Guys ASPired2Poll 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Interspire Trackpoint NX | 14/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page. | |
| Modificada | Alta (7.5) | 1.2% | — | Spiremedia MX7 | 22/12/2005 | 16/6/2026 | SQL injection vulnerability in index.cfm in SpireMedia mx7 allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: the vendor has disputed this issue, stating "This information is incorrect, unproven, and potentially slanderous." However, CVE and OSVDB have both performed additional… | |
| Modificada | Media (4.3) | 0.94% | — | Interspire Fastfind | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Interspire FastFind 2004 and 2005 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Interspire Articlelive NX | 21/11/2005 | 16/6/2026 | SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Interspire Articlelive | 11/5/2005 | 16/6/2026 | ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie. | |
| Modificada | Media (4.3) | 1.4% | — | Interspire Articlelive | 11/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5) BlogId parameter. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Interspire Articlelive | 23/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject arbitrary web script or HTML via the Articleld parameter. |