Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2775▼ 14 respecto a la semana anterior
Críticas / altas1283▼ 250 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 205 respecto a la semana anterior
–

1397 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%—Pensacola WEB Designs Xtreme ASP Photo Gallery15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp.
ModificadaMedia (6.8)1.7%—Lucid Designs Lucid Calendar15/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaAlta (7.5)2.0%—OUT OF THE Trees WEB Design Selectapix9/6/200616/6/2026
Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php.
ModificadaBaja (2.6)2.1%—OUT OF THE Trees WEB Design Selectapix9/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php.
ModificadaMedia (6.8)4.0%💥 ExploitEpic Designs Tinybb1/6/200616/6/2026
Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) password parameters in (b) login.php, and other unspecified vectors.
ModificadaAlta (7.5)1.7%—Epic Designs Eggblog1/6/200616/6/2026
home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter.
ModificadaMedia (5.1)8.8%💥 ExploitEpic Designs Tinybb1/6/200616/6/2026
PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_footers parameter.
ModificadaMedia (6.8)1.6%—Epic Designs Tinybb1/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 allow remote attackers to inject arbitrary web script or HTML via the q parameter in forgot.php, which is echoed in an error message, and other unspecified vectors.
ModificadaMedia (6.4)1.8%💥 ExploitEpic Designs Eggblog1/6/200616/6/2026
SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.1%—OUT OF THE Trees WEB Design Selectapix1/6/200616/6/2026
SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources.
ModificadaMedia (5.1)2.6%💥 ExploitArtmedic Webdesign Artmedic Newsletter26/5/200616/6/2026
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as…
ModificadaMedia (5.1)1.1%—Artmedic Webdesign Artmedic Newsletter26/5/200616/6/2026
artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (7.5)1.9%—Dayfox Designs Dayfox Blog22/5/200616/6/2026
Dayfox Blog 2.0 and earlier stores user credentials in edit/slog_users.txt under the web document root with insufficient access control, which allows remote attackers to gain privileges.
ModificadaMedia (5)1.3%—OUT OF THE Trees WEB Design Selectapix19/5/200616/6/2026
view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter.
ModificadaBaja (2.6)1.2%—Oasyssoft E-business Designer12/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in form_grupo.html in E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.
ModificadaMedia (5)1.4%—Oasyssoft E-business Designer12/5/200616/6/2026
E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web server via "'" characters, and possibly other invalid values, in (1) the id parameter to form_grupo.html, or requests to the (2) archivos/ and (3) files/ directories. NOTE: this issue might be resultant from SQL…
ModificadaMedia (6.8)8.7%—Oasyssoft E-business Designer12/5/200616/6/2026
E-Business Designer (eBD) 3.1.4 y versiones anteriores permite a atacantes remotos subir o modificar archivos arbitrarios y ejecutar código arbitrario, a través de una petición directa a (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html o (3)…
ModificadaMedia (5.8)1.8%💥 ExploitPHP Design X PHP Linkliste4/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter.
ModificadaMedia (5)5.9%💥 ExploitArtmedic Webdesign Artmedic Event1/5/200616/6/2026
PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter.
ModificadaAlta (7.6)1.8%💥 ExploitDesign Nation Dnguestbook11/4/200616/6/2026
SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters.
ModificadaMedia (5.1)1.6%—Wire Plastik Design Wpblog6/4/200616/6/2026
SQL injection vulnerability in index.php in wpBlog 0.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
ModificadaMedia (5.1)1.3%—R2xdesign Qlitenews1/4/200616/6/2026
Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
ModificadaMedia (4.3)1.9%💥 ExploitVihordesign30/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error…
ModificadaMedia (5)3.8%💥 ExploitVihordesign30/3/200616/6/2026
Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.
ModificadaMedia (5.1)1.2%—Arthur Konze Webdesign Akocomment28/3/200616/6/2026
Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter.