Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.0%—Banner Effect Header Project Banner Effect Header3/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the banner_effect_divid parameter in the BannerEffectOptions page to wp-admin/options-general.php.
ModificadaMedia (6.8)1.2%—Banner Effect Header Project Banner Effect Header8/1/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the banner_effect_email parameter in the BannerEffectOptions page to…
ModificadaBaja (3.5)0.95%—Site Banner Project Site Banner21/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the context administration sub-panel in the Site Banner module before 7.x-4.1 for Drupal allows remote authenticated users with the "Administer contexts" Context UI module permission to inject arbitrary web script or HTML via vectors related to context settings.
ModificadaMedia (5.4)0.27%—Civitasmedia Logan Banner21/10/201417/6/2026
The Logan Banner (aka com.soln.S8B5C1F53B8CBE06D5DE0A0E7E23DCDA7) application 1.0010.b0010 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.5)3.6%💥 ExploitBannersky BSK PDF Manager14/7/201417/6/2026
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.
ModificadaMedia (4.3)1.6%—Blogstand Banner Plugin Project Blogstand-smart-banner10/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Blogstand Banner (blogstand-smart-banner) plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bs_blog_id parameter to wp-admin/options-general.php.
ModificadaMedia (4.3)1.6%—Buffercode Random Banner10/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Random Banner plugin 1.1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the buffercode_RBanner_url_banner1 parameter in an update action to wp-admin/options.php.
ModificadaMedia (4.3)1.6%—Stillbreathing Bannerman10/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the BannerMan plugin 0.2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bannerman_background parameter to wp-admin/options-general.php.
ModificadaMedia (4.3)1.6%—Custom Banners Project Custom Banners7/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Custom Banners plugin 1.2.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_banners_registered_name parameter to wp-admin/options.php.
ModificadaMedia (4.3)1.6%—Easy Banners Plugin Project Easy Banners7/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Easy Banners plugin 1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the name parameter to wp-admin/options-general.php.
ModificadaAlta (7.5)1.0%💥 ExploitYourfreeworld Banner Management1/11/201116/6/2026
SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)1.1%💥 ExploitPhpwebscripts Easy Banner Free7/4/201116/6/2026
Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaBaja (2.6)1.8%💥 ExploitPhpwebscripts Easy Banner Free7/4/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl and (2) urlbanner parameters.
ModificadaAlta (7.5)0.99%💥 ExploitE-soft24 Banner Exchange Script22/9/201016/6/2026
SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
ModificadaAlta (7.5)1.1%—Typo3 Sbanner28/7/201016/6/2026
SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)0.84%—Sungard Banner Student12/7/201016/6/2026
Cross-site scripting (XSS) vulnerability in the twbkwbis.P_SecurityQuestion (aka Change Security Question) page in SunGard Banner Student System 7.4 allows remote attackers to inject arbitrary web script or HTML via the New Question field.
ModificadaMedia (4.3)1.0%—Phpbannerexchange Project Phpbannerexchange9/6/201016/6/2026
Cross-site scripting (XSS) vulnerability in signupconfirm.php in phpBannerExchange 1.2 Arabic allows remote attackers to inject arbitrary web script or HTML via the bannerurl parameter.
ModificadaAlta (7.5)1.00%💥 ExploitAndrews-web Aw-bannerad18/3/201016/6/2026
Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)2.5%💥 ExploitXigla Absolute Banner Manager.net14/7/200916/6/2026
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
ModificadaAlta (7.5)1.1%—Softbizscripts Banner AD Management Script26/6/200916/6/2026
SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbitrary SQL commands via the size_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)3.1%💥 ExploitAdserversolutions Banner Exchange Software2/3/200916/6/2026
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pass parameter). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitEzonescripts Adult Banner Exchange Website10/2/200916/6/2026
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.
ModificadaMedia (4.3)1.7%💥 ExploitSungard Banner Student24/10/200816/6/2026
Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote attackers to inject arbitrary web script or HTML via the addr1 parameter. NOTE: this might be resultant from a CSRF vulnerability, but there are insufficient details to be…
ModificadaAlta (7.5)1.2%💥 ExploitYourfreeworld Banner Management Script21/8/200816/6/2026
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)2.4%💥 ExploitHiox India Banner Rotator10/7/200816/6/2026
PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.
Orbitaley — Vulnerabilidades