Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
120 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Pulseinfotech COM Flipwall | 17/11/2010 | 16/6/2026 | SQL injection vulnerability in the Pulse Infotech Flip Wall (com_flipwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | F-cimag-in COM Bookflip | 9/7/2009 | 16/6/2026 | SQL injection vulnerability in the BookFlip (com_bookflip) component 2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter to index.php. | |
| Modificada | Media (4.3) | 5.8% | 💥 Exploit | Wordpress Page Flip Image Gallery Plugin | 30/12/2008 | 16/6/2026 | Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the book_id parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 1.8% | — | Flip4mac WMV | 16/9/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Adam Scheinberg Flip | 25/7/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in Adam Scheinberg Flip 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Joomla COM FlippingbookMambo COM FlippingbookPage-flip-tools Flipping Book | 6/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter. | |
| Modificada | Alta (9.3) | 1.3% | — | Flip4mac WMV | 16/4/2008 | 16/6/2026 | Unspecified vulnerability in Flip4Mac WMV before 2.2.0.49 has unknown impact and attack vectors related to malformed WMV files. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Invision Power Services Invision Power BoardPhpbbSebflipper Multi-forums Module | 29/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in directory.php in the Multi-Forums (aka Multi Host Forum Pro) module 1.3.3, for phpBB and Invision Power Board (IPB or IP.Board), allow remote attackers to execute arbitrary SQL commands via the (1) go and (2) cat parameters. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Adam Scheinberg Flip | 24/9/2007 | 16/6/2026 | Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Adam Scheinberg Flip | 24/9/2007 | 16/6/2026 | account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register action. | |
| Modificada | Alta (9.3) | 34% | 💥 Exploit | E-book Systems Flipviewer | 6/6/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the FViewerLoading ActiveX control (FlipViewerX.dll) in E-Book Systems FlipViewer before 4.1 allow remote attackers to cause a denial of service (crash) or execute arbitrary code via long (1) UID, (2) Opf, (3) PAGENO, (4) LaunchMode, (5) SubID, (6) BookID, (7) LibraryID, (8)… | |
| Modificada | Alta (7.5) | 1.4% | — | Franklin Huang Flip-search-add-on | 19/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in everything.php in Franklin Huang Flip (aka Flip-search-add-on) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the incpath parameter. | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Flipsource Flip | 6/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_path parameter. | |
| Modificada | Alta (10) | 6.2% | 💥 Exploit | Telestream Flip4mac Windows Media Components FOR Quicktime | 31/1/2007 | 16/6/2026 | Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption. | |
| Modificada | Alta (10) | 7.9% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Multiple buffer overflows in Winamp Web Interface (Wawi) 7.5.13 and earlier (1) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an (a) long username or a (b) crafted packet to the FindBasicAuth function in security.cpp, related to the /browse URI; and… | |
| Modificada | Baja (3.5) | 1.3% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter. | |
| Modificada | Baja (3.5) | 1.4% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | The CControl::Download function (/dl URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to download arbitrary file types under the root via a trailing "." (dot) in a filename in the file parameter, related to erroneous behavior of the IsWinampFile function. | |
| Modificada | Baja (3.5) | 1.3% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target… | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Flipper Poll | 21/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Flip | 20/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in FLIP 0.9.0.1029 allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter in text.php and (2) frame parameter in forum.php. |