Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.3% | — | Tomatocart | 31/10/2012 | 16/6/2026 | TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Tomatosoft Free MP3 Player | 30/12/2011 | 16/6/2026 | TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow. | |
| Modificada | Media (5) | 1.2% | — | Tomatocart | 24/9/2011 | 16/6/2026 | TomatoCart 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/system/offline.php and certain other files. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Toughtomato COM Ttvideo | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video action to index.php. | |
| Modificada | Media (5.1) | 0.79% | 💥 Exploit | Tomatocms | 15/6/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in TomatoCMS 2.0.6 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password. | |
| Modificada | Media (4.3) | 0.84% | — | Tomatocms | 15/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword or (2) bannerid parameter in conjunction with a /admin/ad/banner/list PATH_INFO; and allow remote authenticated users, with certain privileges, to inject… | |
| Modificada | Baja (2.6) | 1.0% | — | Tomatocms | 15/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword or (2) article-id parameter in conjunction with a /admin/news/article/list PATH_INFO; the (3) keyword parameter in conjunction with a… | |
| Modificada | Media (6) | 0.95% | — | Tomatocms | 15/6/2010 | 16/6/2026 | Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory. | |
| Modificada | Baja (2.1) | 1.2% | — | Tomatocms | 20/5/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with certain creation privileges, to inject arbitrary web script or HTML via the (1) content parameter in conjunction with a /admin/poll/add PATH_INFO, the (2) meta parameter in conjunction with… | |
| Modificada | Baja (2.1) | 1.0% | — | Tomatocms | 20/5/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with "Add new article" privileges, to inject arbitrary web script or HTML via the (1) title, (2) subTitle, and (3) author parameters in conjunction with a /admin/news/article/add PATH_INFO. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Tomatocms | 20/5/2010 | 16/6/2026 | SQL injection vulnerability in index.php in TomatoCMS before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the q parameter in conjunction with a /news/search PATH_INFO. |