Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.2% | 💥 Exploit | Dream-multimedia-tv Enigma2 Webinterface | 8/2/2012 | 16/6/2026 | Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Webidsupport Webid | 7/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in confirm.php in WeBid 0.8.5 P1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (5) | 1.2% | — | Webinsta Mailing List Manager | 24/9/2011 | 16/6/2026 | WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files. | |
| Modificada | Media (5) | 1.9% | — | Webidsupport Webid | 24/9/2011 | 16/6/2026 | WeBid 1.0.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by js/calendar.php and certain other files. | |
| Modificada | Alta (10) | 1.5% | — | IBM Webi | 5/4/2011 | 16/6/2026 | Unspecified vulnerability in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Webi | 5/4/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) 1.0.4 before FP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-1242. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Winterwebs Ezwebitor | 12/7/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL commands via the (1) txtUserId (Username) and (2) txtPassword (Password) parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | IBM Webi | 5/4/2010 | 16/6/2026 | The IBM Web Interface for Content Management (aka WEBi) before 1.0.4 creates persistent cookies on client workstations, which has unspecified impact and attack vectors. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Webi | 5/4/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Webilix Wx-guestbook | 23/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Webilix Wx-guestbook | 23/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Webidsupport Webid | 28/8/2009 | 16/6/2026 | SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Webidsupport Webid | 28/8/2009 | 16/6/2026 | WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log. | |
| Modificada | Media (5) | 1.7% | 💥 Exploit | Webidsupport Webid | 28/8/2009 | 16/6/2026 | eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. NOTE: this can probably be leveraged for cross-site scripting (XSS) attacks. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Webidsupport Webid | 28/8/2009 | 16/6/2026 | SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | RSA Webid | 24/3/2008 | 16/6/2026 | Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118. | |
| Modificada | Media (4.3) | 1.1% | — | Ifnet Webif | 24/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/webif.exe in ifnet WebIf allows remote attackers to inject arbitrary web script or HTML via the cmd parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Webixir Efendy Blog | 4/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ara.asp in Efendy Blog 1.0 allows remote attackers to inject arbitrary web script or HTML via the ara parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (9) | 7.9% | 💥 Exploit | Ifnet Webif.cgi | 19/6/2007 | 16/6/2026 | Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter. | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Webinsta FM Manager | 24/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter, a different product and vector than CVE-2005-0748. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Webinsta CMS | 17/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different vulnerability than CVE-2006-4196. NOTE: the provenance of this information is unknown; the details are obtained from… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Webinsta Mailing List Manager | 17/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter. | |
| Modificada | Alta (7.5) | 9.9% | 💥 Exploit | Webinsta CMS | 17/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the templates_dir parameter. | |
| Modificada | Media (5) | 1.3% | — | Businessobjects Webintelligence | 15/12/2005 | 16/6/2026 | Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related to "authentication mechanisms" and "form input." | |
| Modificada | Media (5) | 1.6% | — | SPI Dynamics Webinspect | 3/8/2005 | 16/6/2026 | Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Javascript from one application into another. |