Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 10% | 💥 Exploit | HP System Management Homepage | 28/4/2010 | 16/6/2026 | Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter. | |
| Modificada | Media (4.6) | 1.8% | — | HP System Management Homepage | 23/4/2010 | 16/6/2026 | Unspecified vulnerability in HP System Management Homepage (SMH) 6.0 before 6.0.0-95 on Linux, and 6.0 before 6.0.0.96 on Windows, allows remote authenticated users to obtain sensitive information, modify data, and cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 2.8% | — | HP System Management Homepage | 5/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter. | |
| Modificada | Media (4.3) | 1.1% | — | 4homepages 4images | 8/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in includes/functions.php in 4images 1.7 through 1.7.7 allows remote attackers to inject arbitrary web script or HTML via vectors related to the url variable. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | 4homepages 4images | 19/6/2009 | 16/6/2026 | Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter. | |
| Modificada | Baja (3.5) | 1.6% | 💥 Exploit | 4homepages 4images | 19/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a picture. | |
| Modificada | Media (4.3) | 2.9% | — | HP System Management Homepage | 19/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Analizada | Media (6.8) | 2.1% | 💥 Exploit | Iss-oberlausitz Bluepage CMS | 3/2/2009 | 16/6/2026 | Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |
| Analizada | Media (4.3) | 1.1% | — | Iss-oberlausitz Bluepage CMS | 3/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in BLUEPAGE CMS 2.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) whl, (2) var_1, and (3) search parameters. | |
| Modificada | Media (6.2) | 0.30% | — | HP System Management Homepage | 4/11/2008 | 16/6/2026 | Unspecified vulnerability in HP System Management Homepage (SMH) 2.2.6 and earlier on HP-UX B.11.11 and B.11.23, and SMH 2.2.6 and 2.2.8 and earlier on HP-UX B.11.23 and B.11.31, allows local users to gain "unauthorized access" via unknown vectors, possibly related to temporary file permissions. | |
| Modificada | Media (4.3) | 2.9% | — | HP System Management Homepage | 13/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.15.210 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-1663. | |
| Modificada | Media (4.3) | 3.2% | — | HP System Management Homepage | 9/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) 2.1.10 and 2.1.11 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Wikepage Opus | 25/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbitrary web script or HTML via the wiki parameter. | |
| Modificada | Media (5) | 1.5% | — | Wikepage Opus | 18/4/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to read arbitrary files via directory traversal sequences in the wiki parameter, a different vector than CVE-2006-4418. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | PHP Homepage M | 9/10/2007 | 16/6/2026 | SQL injection vulnerability in galerie.php in PHP Homepage M (phpHPm) 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action. | |
| Modificada | Media (4.3) | 1.1% | — | Wikepage Opus | 9/10/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in (a) Wikepage Opus 13 2007.2 and (b) TipiWiki 2 allow remote attackers to inject arbitrary web script or HTML via the (1) PageContent and (2) PageName parameters. | |
| Modificada | Baja (2.1) | 0.48% | — | HP System Management Homepage | 18/9/2007 | 16/6/2026 | HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probably related to previous vulnerabilities for OpenSSL. | |
| Modificada | Alta (9) | 3.8% | — | HP System Management Homepage | 19/6/2007 | 16/6/2026 | HP System Management Homepage (SMH) before 2.1.9 for Linux, when used with Novell eDirectory, assigns the eDirectory members to the root group, which allows remote authenticated eDirectory users to gain privileges. | |
| Modificada | Media (4.3) | 3.9% | — | HP System Management Homepage | 6/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 2.1.2 running on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | MY Little Homepage MY Little Forum | 31/5/2007 | 16/6/2026 | SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | MY Little Homepage MY Little Forum | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in my little forum 1.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php and (2) timedifference.php. | |
| Modificada | Media (6.8) | 1.2% | — | MY Little Homepage MY Little Weblog | 18/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vector than CVE-2006-6087. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Enthrallweb Epages | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in actualpic.asp in Enthrallweb ePages allows remote attackers to execute arbitrary SQL commands via the Biz_ID parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | MY Little Homepage MY Little Weblog | 24/11/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in weblog.php in my little weblog allows remote attackers to inject arbitrary web script or HTML via the action parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | 4homepages 4images | 11/10/2006 | 16/6/2026 | SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter. |