Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.2%💥 ExploitDream-multimedia-tv Enigma2 Webinterface8/2/201216/6/2026
Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
ModificadaMedia (4.3)1.8%💥 ExploitWebidsupport Webid7/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaMedia (5)1.2%—Webinsta Mailing List Manager24/9/201116/6/2026
WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files.
ModificadaMedia (5)1.9%—Webidsupport Webid24/9/201116/6/2026
WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files.
ModificadaAlta (10)1.5%—IBM Webi5/4/201116/6/2026
Unspecified vulnerability in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 has unknown impact and attack vectors.
ModificadaMedia (4.3)1.1%—IBM Webi5/4/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1242.
ModificadaAlta (7.5)1.0%💥 ExploitWinterwebs Ezwebitor12/7/201016/6/2026
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%—IBM Webi5/4/201016/6/2026
The IBM Web Interface for Content Management (aka WEBi) before 1.0.4 creates persistent cookies on client workstations, which has unspecified impact and attack vectors.
ModificadaMedia (4.3)1.1%—IBM Webi5/4/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.2%💥 ExploitWebilix Wx-guestbook23/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.93%💥 ExploitWebilix Wx-guestbook23/9/200916/6/2026
Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitWebidsupport Webid28/8/200916/6/2026
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5)2.4%💥 ExploitWebidsupport Webid28/8/200916/6/2026
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.
ModificadaMedia (5)1.7%💥 ExploitWebidsupport Webid28/8/200916/6/2026
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. NOTE: this can probably be leveraged for cross-site scripting (XSS) attacks.
ModificadaAlta (7.5)0.97%💥 ExploitWebidsupport Webid28/8/200916/6/2026
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.
ModificadaMedia (4.3)1.5%💥 ExploitRSA Webid24/3/200816/6/2026
Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118.
ModificadaMedia (4.3)1.1%—Ifnet Webif24/10/200716/6/2026
Cross-site scripting (XSS) vulnerability in cgi-bin/webif.exe in ifnet WebIf allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.
ModificadaMedia (4.3)1.0%—Webixir Efendy Blog4/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in ara.asp in Efendy Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the ara parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (9)7.9%💥 ExploitIfnet Webif.cgi19/6/200716/6/2026
Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter.
ModificadaMedia (6.8)3.1%💥 ExploitWebinsta FM Manager24/4/200716/6/2026
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748.
ModificadaAlta (7.5)2.2%💥 ExploitWebinsta CMS17/8/200616/6/2026
PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different vulnerability than CVE-2006-4196. NOTE: the provenance of this information is unknown; the details are obtained from…
ModificadaAlta (7.5)3.5%💥 ExploitWebinsta Mailing List Manager17/8/200616/6/2026
PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter.
ModificadaAlta (7.5)9.9%💥 ExploitWebinsta CMS17/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the templates_dir parameter.
ModificadaMedia (5)1.3%—Businessobjects Webintelligence15/12/200516/6/2026
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related to "authentication mechanisms" and "form input."
ModificadaMedia (5)1.6%—SPI Dynamics Webinspect3/8/200516/6/2026
Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Javascript from one application into another.
Orbitaley — Vulnerabilidades