Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
89 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Stephane Pineau Vote | 17/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in depouilg.php3 in Stephane Pineau VOTE 1c allow remote attackers to execute arbitrary PHP code via a URL in the (1) NomVote and (2) FilePalHex parameters. | |
| Modificada | Alta (7.5) | 1.4% | — | JX Development Phpvoter | 1/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions.inc.php in phpVoter 0.6 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter. | |
| Modificada | Alta (7.6) | 6.1% | 💥 Exploit | Vivotek Mjpegcontrol | 11/6/2007 | 16/6/2026 | Stack-based buffer overflow in the Vivotek Motion Jpeg ActiveX control (aka MjpegControl) in MjpegDecoder.dll 2.0.0.13 allows remote attackers to execute arbitrary code via a long PtzUrl property value. | |
| Modificada | Media (6.8) | 2.7% | — | Allons Voter | 12/2/2007 | 16/6/2026 | Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php. NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Vote PRO | 26/1/2007 | 16/6/2026 | Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitrary code via requests to unspecified PHP scripts with the poll_id parameter, which is supplied to eval function calls, a different set of vectors than CVE-2007-0504. NOTE: The provenance of this… | |
| Modificada | Alta (10) | 6.2% | 💥 Exploit | Vote PRO | 26/1/2007 | 16/6/2026 | Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to execute arbitrary code via the poll_id parameter, which is supplied to an eval function call, a different vulnerability type than CVE-2005-4632. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Cwm-design Cwmvote | 26/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the abs parameter. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Azerbaijan Development Group Azdgvote | 13/4/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Azerbaijan Design & Development Group (AZDG) AzDGVote allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter in (1) vote.php, (2) view.php, (3) admin.php, and (4) admin/index.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Vote PRO | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Comdev Vote Caster | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Comdev Vote Caster 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a result action. | |
| Modificada | Alta (7.5) | 1.7% | — | Pollvote | 23/11/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in pollvote.php in PollVote allows remote attackers to include arbitrary files via a URL in the pollname parameter. | |
| Modificada | Media (5) | 3.3% | — | Mike Spice Mikes Vote CGI | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in vote.cgi for Mike Spice Mike's Vote CGI before 1.3 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the type parameter. | |
| Modificada | Media (5) | 6.6% | 💥 Exploit | Steve Korbett Pvote | 18/6/2002 | 16/6/2026 | PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete polls by modifying parameters to (1) add.php or (2) del.php. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Steve Korbett Pvote | 18/6/2002 | 16/6/2026 | PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling ch_info.php with the newpass and confirm parameters both set to the new password. |