Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.0% | — | Banner Effect Header Project Banner Effect Header | 3/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the banner_effect_divid parameter in the BannerEffectOptions page to wp-admin/options-general.php. | |
| Modificada | Media (6.8) | 1.2% | — | Banner Effect Header Project Banner Effect Header | 8/1/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Banner Effect Header plugin 1.2.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the banner_effect_email parameter in the BannerEffectOptions page to… | |
| Modificada | Baja (3.5) | 0.95% | — | Site Banner Project Site Banner | 21/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the context administration sub-panel in the Site Banner module before 7.x-4.1 for Drupal allows remote authenticated users with the "Administer contexts" Context UI module permission to inject arbitrary web script or HTML via vectors related to context settings. | |
| Modificada | Media (5.4) | 0.27% | — | Civitasmedia Logan Banner | 21/10/2014 | 17/6/2026 | The Logan Banner (aka com.soln.S8B5C1F53B8CBE06D5DE0A0E7E23DCDA7) application 1.0010.b0010 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.5) | 3.6% | 💥 Exploit | Bannersky BSK PDF Manager | 14/7/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 1.6% | — | Blogstand Banner Plugin Project Blogstand-smart-banner | 10/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Blogstand Banner (blogstand-smart-banner) plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bs_blog_id parameter to wp-admin/options-general.php. | |
| Modificada | Media (4.3) | 1.6% | — | Buffercode Random Banner | 10/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Random Banner plugin 1.1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the buffercode_RBanner_url_banner1 parameter in an update action to wp-admin/options.php. | |
| Modificada | Media (4.3) | 1.6% | — | Stillbreathing Bannerman | 10/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the BannerMan plugin 0.2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the bannerman_background parameter to wp-admin/options-general.php. | |
| Modificada | Media (4.3) | 1.6% | — | Custom Banners Project Custom Banners | 7/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Custom Banners plugin 1.2.2.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_banners_registered_name parameter to wp-admin/options.php. | |
| Modificada | Media (4.3) | 1.6% | — | Easy Banners Plugin Project Easy Banners | 7/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Easy Banners plugin 1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the name parameter to wp-admin/options-general.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Yourfreeworld Banner Management | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in trackads.php in YourFreeWorld Banner Management allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Phpwebscripts Easy Banner Free | 7/4/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Baja (2.6) | 1.8% | 💥 Exploit | Phpwebscripts Easy Banner Free | 7/4/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl and (2) urlbanner parameters. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | E-soft24 Banner Exchange Script | 22/9/2010 | 16/6/2026 | SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbitrary SQL commands via the targetid parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 Sbanner | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 0.84% | — | Sungard Banner Student | 12/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the twbkwbis.P_SecurityQuestion (aka Change Security Question) page in SunGard Banner Student System 7.4 allows remote attackers to inject arbitrary web script or HTML via the New Question field. | |
| Modificada | Media (4.3) | 1.0% | — | Phpbannerexchange Project Phpbannerexchange | 9/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signupconfirm.php in phpBannerExchange 1.2 Arabic allows remote attackers to inject arbitrary web script or HTML via the bannerurl parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Andrews-web Aw-bannerad | 18/3/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) User and (2) Password parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Xigla Absolute Banner Manager.net | 14/7/2009 | 16/6/2026 | Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. | |
| Modificada | Alta (7.5) | 1.1% | — | Softbizscripts Banner AD Management Script | 26/6/2009 | 16/6/2026 | SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbitrary SQL commands via the size_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Adserversolutions Banner Exchange Software | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote attackers to execute arbitrary SQL commands via the (1) username (uname parameter) and (2) password (pass parameter). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ezonescripts Adult Banner Exchange Website | 10/2/2009 | 16/6/2026 | SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Sungard Banner Student | 24/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the contact update page (ss/bwgkoemr.P_UpdateEmrgContacts) in SunGard Banner Student 7.3 allows remote attackers to inject arbitrary web script or HTML via the addr1 parameter. NOTE: this might be resultant from a CSRF vulnerability, but there are insufficient details to be… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Yourfreeworld Banner Management Script | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Hiox India Banner Rotator | 10/7/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter. |