Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Artifectx Xclassified | 9/7/2014 | 17/6/2026 | SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Openclassifieds Open Classifieds 2 | 14/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/. | |
| Modificada | Alta (7.5) | 1.3% | — | Etoshop Classifieds Creator | 24/12/2013 | 17/6/2026 | Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp. | |
| Modificada | Media (5.8) | 0.57% | — | Opensourceclassifieds | 4/11/2012 | 16/6/2026 | Open Source Classifieds does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function. | |
| Modificada | Alta (10) | 2.6% | — | Awpcp Another Wordpress Classifieds Plugin | 6/9/2012 | 16/6/2026 | Unspecified vulnerability in the Another WordPress Classifieds Plugin before 2.0 for WordPress has unknown impact and attack vectors related to "image uploads." | |
| Modificada | Baja (3.5) | 0.93% | 💥 Exploit | Dclassifieds | 7/2/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in admin/settings/update in DClassifieds 0.1 final allows remote attackers to hijack the authentication of administrators for requests that modify account settings such as the administrator password or email via certain Settings[] parameters. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | 2daybiz Online Classified Script | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arbitrary SQL commands via the alb parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | 2daybiz Online Classified Script | 2/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Deltascripts PHP Classifieds | 8/10/2011 | 16/6/2026 | PHP remote file inclusion vulnerability in tools/phpmailer/class.phpmailer.php in PHP Classifieds 7.3 allows remote attackers to execute arbitrary PHP code via a URL in the lang_path parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Sellatsite PHP Classifieds ADS | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL commands via the sid parameter. | |
| Modificada | Media (5) | 1.3% | — | Kamads Classifieds 2 B3 | 23/9/2011 | 16/6/2026 | Kamads Classifieds 2_B3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by V2A_XHTML/style/view.php and certain other files. | |
| Modificada | Media (4.3) | 1.1% | — | Open-classifieds Open Classifieds | 16/9/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Open Classifieds 1.7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) desc, (2) price, (3) title, and (4) place parameters to index.php and the (5) subject parameter to contact.htm, related to content/contact.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Site2nite Boat Classifieds | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in detail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Site2nite Boat Classifieds | 12/7/2010 | 16/6/2026 | SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the Id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Clscript Classifieds Script | 3/5/2010 | 16/6/2026 | SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitrary SQL commands via the hpId parameter. | |
| Modificada | Media (4.3) | 0.93% | — | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to inject arbitrary web script or HTML via the address parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the siteid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tukanas Easyclassifieds Script | 15/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Tukanas Classifieds (aka EasyClassifieds) Script 1.0 allows remote attackers to execute arbitrary SQL commands via the b parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Resalecode Classified Linktrader Script | 10/3/2010 | 16/6/2026 | SQL injection vulnerability in addlink.php in Classified Linktrader Script allows remote attackers to execute arbitrary SQL commands via the slctCategories parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Yourfreeworld Ultra Classifieds PRO | 2/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in listads.php in YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject arbitrary web script or HTML via the cn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Yourfreeworld Ultra Classifieds PRO | 2/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php. | |
| Modificada | Media (4.3) | 1.1% | — | Almondsoft Affiliate Network ClassifiedsAlmondsoft Almond Classifieds | 16/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to inject arbitrary web script or HTML via the city parameter in a search action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Almondsoft Affiliate Network ClassifiedsAlmondsoft Almond Classifieds | 16/9/2009 | 16/6/2026 | SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Almondsoft Almond Classifieds | 16/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse action to index.php or (2) the addr parameter to gmap.php. NOTE: some… |