Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2775▼ 14 respecto a la semana anterior
Críticas / altas1283▼ 250 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 205 respecto a la semana anterior
1397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Pensacola WEB Designs Xtreme ASP Photo Gallery | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp. | |
| Modificada | Media (6.8) | 1.7% | — | Lucid Designs Lucid Calendar | 15/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.0% | — | OUT OF THE Trees WEB Design Selectapix | 9/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php. | |
| Modificada | Baja (2.6) | 2.1% | — | OUT OF THE Trees WEB Design Selectapix | 9/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php. | |
| Modificada | Media (6.8) | 4.0% | 💥 Exploit | Epic Designs Tinybb | 1/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) password parameters in (b) login.php, and other unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Epic Designs Eggblog | 1/6/2006 | 16/6/2026 | home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter. | |
| Modificada | Media (5.1) | 8.8% | 💥 Exploit | Epic Designs Tinybb | 1/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_footers parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Epic Designs Tinybb | 1/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 allow remote attackers to inject arbitrary web script or HTML via the q parameter in forgot.php, which is echoed in an error message, and other unspecified vectors. | |
| Modificada | Media (6.4) | 1.8% | 💥 Exploit | Epic Designs Eggblog | 1/6/2006 | 16/6/2026 | SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | OUT OF THE Trees WEB Design Selectapix | 1/6/2006 | 16/6/2026 | SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources. | |
| Modificada | Media (5.1) | 2.6% | 💥 Exploit | Artmedic Webdesign Artmedic Newsletter | 26/5/2006 | 16/6/2026 | artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as… | |
| Modificada | Media (5.1) | 1.1% | — | Artmedic Webdesign Artmedic Newsletter | 26/5/2006 | 16/6/2026 | artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 1.9% | — | Dayfox Designs Dayfox Blog | 22/5/2006 | 16/6/2026 | Dayfox Blog 2.0 and earlier stores user credentials in edit/slog_users.txt under the web document root with insufficient access control, which allows remote attackers to gain privileges. | |
| Modificada | Media (5) | 1.3% | — | OUT OF THE Trees WEB Design Selectapix | 19/5/2006 | 16/6/2026 | view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter. | |
| Modificada | Baja (2.6) | 1.2% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in form_grupo.html in E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection. | |
| Modificada | Media (5) | 1.4% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web server via "'" characters, and possibly other invalid values, in (1) the id parameter to form_grupo.html, or requests to the (2) archivos/ and (3) files/ directories. NOTE: this issue might be resultant from SQL… | |
| Modificada | Media (6.8) | 8.7% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | E-Business Designer (eBD) 3.1.4 y versiones anteriores permite a atacantes remotos subir o modificar archivos arbitrarios y ejecutar código arbitrario, a través de una petición directa a (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html o (3)… | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | PHP Design X PHP Linkliste | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Artmedic Webdesign Artmedic Event | 1/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter. | |
| Modificada | Alta (7.6) | 1.8% | 💥 Exploit | Design Nation Dnguestbook | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters. | |
| Modificada | Media (5.1) | 1.6% | — | Wire Plastik Design Wpblog | 6/4/2006 | 16/6/2026 | SQL injection vulnerability in index.php in wpBlog 0.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | |
| Modificada | Media (5.1) | 1.3% | — | R2xdesign Qlitenews | 1/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Vihordesign | 30/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error… | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Vihordesign | 30/3/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter. | |
| Modificada | Media (5.1) | 1.2% | — | Arthur Konze Webdesign Akocomment | 28/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter. |