Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 5 respecto a la semana anterior
Críticas / altas1274▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
1397 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Abledesign D-man | 21/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | Abledesign | 21/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AbleDesign ReSearch 2.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.4% | — | Sensation Designs Kbase Express | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to category.php and (2) search parameters to search.php. | |
| Modificada | Media (4.3) | 0.95% | — | CJ Design CJ TAG Board | 14/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in details.php in CjTagBoard 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date, (2) time, (3) name, (4) ip, (5) agent, or (6) msg parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Pensacola WEB Designs Xtremeasp Photogallery | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | The (1) modules.php, (2) block-Calendar.php, (3) block-Calendar1.php, (4) block-Calendar_center.php scripts in NukeCalendar 1.1.a, as used in PHP-Nuke, allow remote attackers to obtain sensitive information via a URL with an invalid argument, which reveals the full path in an error message. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Francisco Burzi Php-nukeShiba-design Nukecalendar | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modules.php in NukeCalendar 1.1.a, as used in PHP-Nuke, allows remote attackers to inject arbitrary web script or HTML via the eid parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Artmedic Webdesign Artmedic Links | 6/12/2004 | 16/6/2026 | Vulnerabiliad de inyección remota de código PHP en index.php de Artmedic links 5.0 (artmedic_links5) permite a atacantes remotos ejecutar código PHP de su elección modificando el parámetro id para referenciar a una URL en un servidor web remoto que contiene el código. | |
| Modificada | Alta (7.5) | 1.5% | — | Wire Plastic Design Wpquiz | 30/7/2004 | 16/6/2026 | WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Esignal | 25/3/2004 | 16/6/2026 | Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag. | |
| Modificada | Media (4.3) | 1.0% | — | Affordable WEB Space Design Webbbs | 7/8/2003 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el libro de visitas de WebBBS permite a atacantes remotos insertar script web arbitrario mediante los campos Nombre, Correo Electrónico, o Mensaje. | |
| Modificada | Media (5) | 1.8% | — | Bizdesign Imagefolio | 31/12/2002 | 16/6/2026 | ImageFolio 2.23 through 2.27 allows remote attackers to obtain sensitive information via a nonexistent image category, which leaks the web root in the resulting error message. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Affordable WEB Space Design Webbbs | 31/12/2002 | 16/6/2026 | webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter. | |
| Modificada | Media (5) | 1.5% | — | Sapio Design LTD Webreflex | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Sapio Design Ltd. WebReflex 1.53 allows remote attackers to read arbitrary files via a .. in an HTTP request. | |
| Modificada | Alta (7.5) | 1.5% | — | Bizdesign Imagefolio | 31/12/2002 | 16/6/2026 | The default configuration of BizDesign ImageFolio 2.23 through 2.26 does not control access to (1) admin/setup.cgi, which allows remote attackers to create an administrative account, or (2) admin/nph-build.cgi, which allows remote attackers to cause a denial of service (CPU consumption). | |
| Modificada | Baja (2.1) | 0.35% | — | Shana Informed DesignerShana Informed Filler | 31/12/2002 | 16/6/2026 | Informed (1) Designer and (2) Filler 3.05 does not zero out newly allocated disk blocks as an encrypted file grows in size, which may allow attackers to obtain sensitive information. | |
| Modificada | Media (6.8) | 4.7% | 💥 Exploit | Bizdesign Imagefolio | 11/12/2002 | 16/6/2026 | Vulnerabilidad de scripting en sitios cruzados (XSS) en BizDesign Imageolio 3.01 y anteriores permiten a atacantes remotos ejecutar código web arbitrario como otros usuarios mediante el parámetro directo en imageFolio.cgi, o nph-build.cgi | |
| Modificada | Baja (2.1) | 0.42% | — | Nevrona Designs Miramail | 25/3/2002 | 16/6/2026 | Nevrona Diseña MiraMail 1.04 y anteriores almacenan información de autenticación, nombres de usuario y contraseñas en texto plano de los ficheros .ini, que permite a un atacante utilizar los privilegios de los usuarios capturados en esos ficheros. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Sapio Design LTD Webreflex | 3/5/2001 | 16/6/2026 | Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Armada Design Master Index | 19/12/2000 | 23/9/2026 | Vulnerabilidad de salto de directorio en el script CGI search.cgi de Armada Master Index permite a atacantes remotos leer archivos arbitrarios mediante un ataque de '..' (punto punto) en el parámetro 'catigory'. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Generation Terrorists Designs AND Concepts Sojourn | 14/3/2000 | 16/6/2026 | Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack. |