Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

1063 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.9%—Hosting Controller14/3/200616/6/2026
SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaBaja (2.6)5.0%💥 ExploitDavid Ravenscroft Hithost10/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php.
ModificadaMedia (6.5)2.3%💥 ExploitFree Host Shop Website Generator28/2/200616/6/2026
Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.
ModificadaAlta (7.5)1.6%—Scriptme SME GB Host23/2/200616/6/2026
SQL injection vulnerability in login.php in Scriptme SmE GB Host 1.21 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the Username parameter.
ModificadaAlta (7.5)7.3%💥 ExploitDreamcost Hostadmin19/2/200616/6/2026
PHP remote file inclusion vulnerability in index.php in DreamCost HostAdmin allows remote attackers to include arbitrary files via the $path variable, which is not initialized before use.
ModificadaMedia (4.3)1.3%—Virtual Hosting Control System15/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the…
ModificadaAlta (10)5.2%💥 ExploitVirtual Hosting Control System15/2/200616/6/2026
The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.
ModificadaAlta (10)2.9%—Virtual Hosting Control System15/2/200616/6/2026
add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.
ModificadaAlta (7.5)3.1%💥 ExploitVirtual Hosting Control System15/2/200616/6/2026
change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.
ModificadaMedia (4.3)1.3%—Scriptme SME Blog HostScriptme SME GB Host13/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in Scriptme SmE GB Host 1.21 and SmE Blog Host allows remote attackers to inject arbitrary web script or HTML via the BBcode url tag.
ModificadaMedia (6.5)1.8%—Hosting Controller8/2/200616/6/2026
Vulnerabilidad de inyección de SQL en Hosting Controller 6.1 Hotfix 2.8 permite a usuarios remotos autenticados ejecutar órdenes SQL de su elección mediante el parámetro (1) GatewayID en una acción añadir en AddGatewaySettings.asp y (2) el parámetro IP en IPManager.asp.
ModificadaAlta (7.5)2.1%—Nukedweb Guestbookhost4/2/200616/6/2026
Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters.
ModificadaMedia (4.3)1.9%💥 ExploitHelm Hosting Control Panel14/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.
ModificadaMedia (4.3)1.9%💥 ExploitGfhostGmailsite31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.
ModificadaMedia (4.3)1.2%—Zaygo Hostingcart16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi.
ModificadaMedia (4.3)2.2%💥 ExploitVirtual Hosting Control System29/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.
AnalizadaAlta (7.5)4.1%💥 ExploitSoftbizscripts WEB Hosting Directory Script26/11/200516/6/2026
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an…
ModificadaMedia (5)1.4%—Hosting Controller22/9/200516/6/2026
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."
ModificadaMedia (4.6)1.9%💥 ExploitHosting Controller12/7/200516/6/2026
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.
ModificadaMedia (4.3)3.6%💥 ExploitHosting Controller29/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.
ModificadaAlta (7.5)2.1%💥 ExploitHosting Controller1/6/200516/6/2026
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaAlta (7.5)5.6%💥 ExploitHosting Controller27/5/200516/6/2026
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.
ModificadaAlta (7.5)2.5%💥 ExploitHostingcontroller Hosting Controller18/5/200516/6/2026
Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
ModificadaAlta (7.5)1.1%—Virtual Hosting Control System2/5/200516/6/2026
Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries.