Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
1063 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Hosting Controller | 14/3/2006 | 16/6/2026 | SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Baja (2.6) | 5.0% | 💥 Exploit | David Ravenscroft Hithost | 10/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php. | |
| Modificada | Media (6.5) | 2.3% | 💥 Exploit | Free Host Shop Website Generator | 28/2/2006 | 16/6/2026 | Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00. | |
| Modificada | Alta (7.5) | 1.6% | — | Scriptme SME GB Host | 23/2/2006 | 16/6/2026 | SQL injection vulnerability in login.php in Scriptme SmE GB Host 1.21 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the Username parameter. | |
| Modificada | Alta (7.5) | 7.3% | 💥 Exploit | Dreamcost Hostadmin | 19/2/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable, which is not initialized before use. | |
| Modificada | Media (4.3) | 1.3% | — | Virtual Hosting Control System | 15/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the… | |
| Modificada | Alta (10) | 5.2% | 💥 Exploit | Virtual Hosting Control System | 15/2/2006 | 16/6/2026 | The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (10) | 2.9% | — | Virtual Hosting Control System | 15/2/2006 | 16/6/2026 | add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Virtual Hosting Control System | 15/2/2006 | 16/6/2026 | change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access. | |
| Modificada | Media (4.3) | 1.3% | — | Scriptme SME Blog HostScriptme SME GB Host | 13/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to inject arbitrary web script or HTML via the BBcode url tag. | |
| Modificada | Media (6.5) | 1.8% | — | Hosting Controller | 8/2/2006 | 16/6/2026 | Vulnerabilidad de inyección de SQL en Hosting Controller 6.1 Hotfix 2.8 permite a usuarios remotos autenticados ejecutar órdenes SQL de su elección mediante el parámetro (1) GatewayID en una acción añadir en AddGatewaySettings.asp y (2) el parámetro IP en IPManager.asp. | |
| Modificada | Alta (7.5) | 2.1% | — | Nukedweb Guestbookhost | 4/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Helm Hosting Control Panel | 14/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | GfhostGmailsite | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Zaygo Hostingcart | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Virtual Hosting Control System | 29/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script. | |
| Analizada | Alta (7.5) | 4.1% | 💥 Exploit | Softbizscripts WEB Hosting Directory Script | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an… | |
| Modificada | Media (5) | 1.4% | — | Hosting Controller | 22/9/2005 | 16/6/2026 | Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability." | |
| Modificada | Media (4.6) | 1.9% | 💥 Exploit | Hosting Controller | 12/7/2005 | 16/6/2026 | Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Hosting Controller | 29/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Hosting Controller | 1/6/2005 | 16/6/2026 | SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Hosting Controller | 27/5/2005 | 16/6/2026 | Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Hostingcontroller Hosting Controller | 18/5/2005 | 16/6/2026 | Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set. | |
| Modificada | Alta (7.5) | 1.1% | — | Virtual Hosting Control System | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries. |