Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
114 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 24% | 💥 Exploit | Recly Clickheat-heatmap | 31/12/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the Clickheat - Heatmap stats (com_clickheat) component 1.0.1 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[mosConfig_absolute_path] parameter to (a) install.clickheat.php, (b) Cache.php and (c) Clickheat_Heatmap.php… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Easysitenetwork Cheats Complete Website | 19/11/2008 | 16/6/2026 | SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Prozilla Cheats | 17/4/2008 | 16/6/2026 | SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Megacheatz | 28/12/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via the ItemID parameter to (1) comments.php, (2) view.php, (3) siteadmin/ViewItem.php, and unspecified other vectors. | |
| Modificada | Media (6.8) | 1.2% | — | Wheatblog | 4/7/2007 | 16/6/2026 | SQL injection vulnerability in admin/login.php in Wheatblog (wB) 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter. | |
| Modificada | Alta (10) | 4.6% | — | Intervideo Home Theater | 27/4/2007 | 16/6/2026 | Multiple buffer overflows in the WinDVDX ActiveX control in InterVideo Home Theater 2.1.13.0 and 2.5.13.58 allow remote attackers to execute arbitrary code via a long string argument to the (1) GetDiscType or (2) AddFileList method. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (4.3) | 0.92% | — | Wheatblog | 12/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in add_comment.php in Wheatblog (wB) 1.1 allows remote attackers to inject arbitrary web script or HTML via the Email field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue may overlap… | |
| Modificada | Media (5) | 1.3% | — | Wheatblog | 15/11/2006 | 16/6/2026 | index.php in Wheatblog (wB) allows remote attackers to obtain sensitive information via certain values of the postPtr[] and next parameters, which reveals the path in an error message. | |
| Modificada | Media (5.8) | 1.1% | — | Wheatblog | 15/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in add_comment.php in Wheatblog (wB) allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) WWW, and (3) Comment fields. NOTE: this issue may overlap CVE-2006-5195. | |
| Modificada | Media (6.8) | 1.1% | — | Wheatblog | 10/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Wheatblog 1.0 and 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5.1) | 5.8% | 💥 Exploit | Wheatblog | 17/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/session.php in Wheatblog (wB) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wb_class_dir parameter. | |
| Modificada | Media (6.5) | 1.3% | — | Frontrange Iheat | 22/5/2006 | 16/6/2026 | The ActiveX version of FrontRange iHEAT allows remote authenticated users to run arbitrary programs or access arbitrary files on the host machine by uploading a file with an extension that is not associated with an application, and selecting a file from the "Open With..." dialog. | |
| Modificada | Media (5) | 1.6% | — | Gamecheats Advanced WEB Server Professional | 31/12/2002 | 16/6/2026 | advserver.exe in Advanced Web Server (AdvServer) Professional 1.030000 allows remote attackers to cause a denial of service via multiple HTTP requests containing a single carriage return/line feed (CRLF) sequence. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Heat-on Software Hsweb | 3/5/2001 | 16/6/2026 | HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled. |