Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Webblizzard Content Management System | 11/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Mario Valdez Content Management System | 14/5/2008 | 16/6/2026 | Directory traversal vulnerability in cm/graphie.php in Content Management System 0.6.1 for Phprojekt allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cm_imgpath parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Exv2 Content Management System | 15/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965. | |
| Modificada | Alta (7.5) | 1.5% | — | KAI Content Management System | 18/4/2007 | 16/6/2026 | Directory traversal vulnerability in index.php in Kai Content Management System (K-CMS) 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the current_theme parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Exv2 Content Management System | 11/4/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.0.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the set_lang parameter to (1) archive.php, (2) article.php, (3) index.php, or (4) topics.php. | |
| Modificada | Crítica (9.1) | 1.2% | — | Exv2 Content Management System | 11/4/2007 | 16/6/2026 | Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. | |
| Modificada | Media (4.3) | 1.0% | — | Webblizzard Content Management System | 11/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index_cms.php in WebBlizzard CMS allows remote attackers to inject arbitrary web script or HTML via the Suchzeile parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Webblizzard Content Management System | 11/4/2007 | 16/6/2026 | Session fixation vulnerability in WebBlizzard CMS allows remote attackers to hijack web sessions by setting a PHPSESSID cookie. | |
| Modificada | Media (6.8) | 2.6% | 💥 Exploit | Pathos Content Management System | 10/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | |
| Modificada | Alta (10) | 46% | — | Microsoft Content Management Server | 10/4/2007 | 16/6/2026 | Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability." | |
| Modificada | Media (4.3) | 16% | — | Microsoft Content Management Server | 10/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving HTML redirection queries, aka "Cross-site Scripting and Spoofing Vulnerability." | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Net-side.net NET Side Content Management System | 27/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows remote attackers to execute arbitrary PHP code via a URL in the cms parameter. | |
| Modificada | Media (4.3) | 4.7% | 💥 Exploit | Exv2 Content Management System | 2/3/2007 | 16/6/2026 | Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar parameter. | |
| Modificada | Crítica (9.8) | 13% | 💥 Exploit | Exv2 Content Management System | 2/3/2007 | 16/6/2026 | Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'] variable. | |
| Modificada | Media (6.8) | 1.2% | — | Link Content Management Server | 8/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in naprednaPretraga.php in LINK Content Management Server (CMS) allows remote attackers to inject arbitrary web script or HTML via the txtPretraga parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Link Content Management Server | 8/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in LINK Content Management Server (CMS) allow remote attackers to execute arbitrary SQL commands via the (1) IDMeniGlavni parameter to navigacija.php, and the (2) IDStranicaPodaci parameter to prikazInformacije.php. NOTE: The provenance of this information is unknown; the details… | |
| Modificada | Alta (7.5) | 1.2% | — | Bpg-infotech Content Management System | 26/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in an unspecified BPG-InfoTech Content Management System product allow remote attackers to execute arbitrary SQL commands via the (1) vjob parameter in publications_list.asp or (2) InfoID parameter in publication_view.asp. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Phpfaber Content Management System | 31/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE:… | |
| Modificada | Media (5.1) | 2.3% | — | Asbru Software Asbru WEB Content ManagementAsbru Software Asbru Website Manager | 12/10/2006 | 16/6/2026 | The spell checking component of (1) Asbru Web Content Management before 6.1.22, (2) Asbru Web Content Editor before 6.0.22, and (3) Asbru Website Manager before 6.0.22 allows remote attackers to execute arbitrary commands via an unspecified parameter that is not sanitized before Aspell is invoked. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Exv2 Content Management System | 27/9/2006 | 16/6/2026 | SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Inter Network Marketing AG G3 Content Management System | 7/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search module in Inter Network Marketing (INM) CMS G3 allows remote attackers to inject arbitrary web script or HTML via the search_string parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Goldstag Content Management System | 27/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Goldstag Content Management System allows remote attackers to inject arbitrary web script or HTML via the text parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Icms Content Management Systems Icms | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Icms Content Management Systems Icms | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. | |
| Modificada | Media (5.8) | 1.7% | 💥 Exploit | HOT Banana WEB Content Management Suite | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in Hot Banana Web Content Management Suite 5.3 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. |