Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2771▼ 1 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 211 respecto a la semana anterior
1397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.1% | 💥 Exploit | Jjwwebdesign Phpbookingcalendar | 28/3/2006 | 16/6/2026 | SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Dci-designs Dawaween | 7/3/2006 | 16/6/2026 | SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a diwan view action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Dci-designs Dci-taskeen | 1/3/2006 | 16/6/2026 | SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php. | |
| Modificada | Alta (7.5) | 1.8% | — | Hinton Design Phpht Topsites | 13/2/2006 | 16/6/2026 | check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies. | |
| Modificada | Alta (7.5) | 1.3% | — | Hinton Design Phpht Topsites | 13/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Hinton Design Phpht Topsites | 13/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Hinton Design Phphd | 8/2/2006 | 16/6/2026 | check.php in Hinton Design phphd 1.0 does not check passwords when certain cookies are provided, which allows remote attackers to bypass authentication. | |
| Modificada | Media (6.4) | 2.3% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Hinton Design Phphd | 8/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hinton Design phphd 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to check.php or (2) unknown attack vectors to scripts that display information from the database. | |
| Modificada | Media (4.3) | 1.4% | — | Hinton Design Phphd | 8/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in add.php in Hinton Design phphd 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 2.7% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 2.2% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or the id parameter to (2) admin/edit_smilie.php, (3) admin/add_theme.php, (4) admin/ban_ip.php, (5) admin/add_lang.php, or (6)… | |
| Modificada | Baja (1.2) | 0.39% | — | Solar Designer Crypt Blowfish | 8/2/2006 | 16/6/2026 | Las funciones crypt_gensalt de huellas digitales ('hashes') de contraseñas basadas en DES extendidas con estilo BSDI y basadas en MD5 con estilo FreeBSD en crypt_blowfish 0.4.7 y anteriores no distribuyen las sales equitativamente y aleatoriamente en el espacio de huellas digitales, lo que hace más fácil a atacantes… | |
| Modificada | Alta (7.5) | 1.7% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | phpstatus 1.0 does not require passwords when using cookies to identify a user, which allows remote attackers to bypass authentication. | |
| Modificada | Alta (7.5) | 1.4% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpstatus 1.0, when gpc_magic_quotes is disabled, allow remote attackers to execute arbitrary SQL commands and bypass authentication via (1) the username parameter in check.php and (2) unknown attack vectors in the administrative interface. | |
| Modificada | Media (4.3) | 1.3% | — | Hinton Design Phpstatus | 7/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpstatus 1.0 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in the administrative interface. | |
| Modificada | Media (4.6) | 1.3% | — | Adobe AcrobatAdobe Acrobat ReaderAdobe Creative SuiteAdobe Illustrator+5 | 2/2/2006 | 16/6/2026 | Multiple Adobe products, including (1) Photoshop CS2, (2) Illustrator CS2, and (3) Adobe Help Center, install a large number of .EXE and .DLL files with write-access permission for the Everyone group, which allows local users to gain privileges via Trojan horse programs. | |
| Modificada | Media (4.3) | 1.2% | — | Ideosoft Design Ideocontent Manager | 27/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IdeoContent Manager allows remote attackers to inject arbitrary web script or HTML via the (1) goto_id parameter to index.php or (2) page parameter to news_full.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Ideosoft Design Ideocontent Manager | 27/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in IdeoContent Manager allow remote attackers to execute arbitrary SQL commands via the (1) goto_id or (2) mid parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Epic Designs Eggblog | 21/1/2006 | 16/6/2026 | SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Epic Designs Eggblog | 21/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ades Design Adesguestbook | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter. | |
| Modificada | Media (4.6) | 0.59% | — | Autodesk 3DS MAXAutodesk Architectural DesktopAutodesk AutocadAutodesk Autocad Civil 3D+14 | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329. | |
| Modificada | Alta (7.8) | 1.6% | — | Epic Designs Eggblog | 28/12/2005 | 16/6/2026 | search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability. | |
| Modificada | Media (4.3) | 1.2% | — | Epic Designs Eggblog | 28/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields. |