Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1460 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.2%—Dominic Gamble Timesheet.php12/9/200616/6/2026
Vulnerabilidad de inyección SQL en login.php en dwayner79 y Dominic Gamble Timesheet (también conocido como Timesheet.php) 1.2.1 permite a un atacante remoto ejecutar comandos SQL de su elección a través del parámetro de nombre de usuario.
ModificadaAlta (7.5)16%💥 ExploitUltrize Minibill31/8/200616/6/2026
Múltiples vulnerabilidades PHP de inclusión remota de archivo en MiniBill 2006-07-14 (1.2.2) permite a atacantes remotos ejecutar código PHP de su elección mediante (1) una URL en el parámetro config[include_dir] en actions/ipn.php o (2) una ruta FTP en el parámetro config[plugin_dir] en include/initPlugins.php.
ModificadaAlta (7.5)4.2%💥 ExploitMywebland Minibloggie16/8/200616/6/2026
** IMPUGNADA ** Vulnerabilidad de inclusión remota de archivo en PHP en cls_fast_template.php de myWebland miniBloggie 1.0 y anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro fname. NOTA: otro investigador fue incapaz de encontrar una forma de ejecutar código…
ModificadaAlta (7.5)9.8%💥 ExploitMinibb1/8/200616/6/2026
Múltiples vulnerabilidades PHP de inclusión remota de archivo en MiniBB Forum 1.5a permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro absolute_path en (1) news.php, (2) search.php, o (3) whosOnline.php.
ModificadaAlta (7.5)3.8%💥 ExploitMinibb Forum21/7/200616/6/2026
Vulnerabilidades de inclusión remota de archivo en PHP en MiniBB Forum 1.5a y anteriores permite a atacantes remotoso ejecutar código PHP de su elección a través de una URL en el parámetro absolute_path en (1) components/com_minibb.php o (2) components/minibb/index.php.
ModificadaAlta (7.5)1.2%—Dominios Europa Picrate13/6/200616/6/2026
Multiple SQL injection vulnerabilities in Dominios Europa PICRATE (aka TAL RateMyPic) 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) voteid, and (3) vfiel parameters to (a) index.php, and via the (4) nick, (5) email, (6) city, (7) messen, and (8) message form field parameters to (b)…
ModificadaMedia (6.8)1.2%—Dominios Europa Picrate5/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dominios Europa PICRATE (aka TAL RateMyPic) 1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the (1) name (aka nick), (2) email, and (3) comment boxes; and via the (4) id…
ModificadaAlta (7.5)2.0%💥 ExploitMini-nuke1/6/200616/6/2026
SQL injection vulnerability in Your_Account.asp in Mini-Nuke 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) yas_1, (2) yas_2, and (3) yas_3 parameters.
ModificadaMedia (5)1.4%—Mini-nuke1/6/200616/6/2026
membership.asp in Mini-Nuke 2.3 and earlier uses plaintext security codes, which allows remote attackers to register multiple times via automated scripts.
ModificadaMedia (5)1.6%—Mini-nuke1/6/200616/6/2026
enter.asp in Mini-Nuke 2.3 and earlier makes it easier for remote attackers to conduct password guessing attacks by setting the guvenlik parameter to the same value as the hidden gguvenlik parameter, which bypasses a verification step because the gguvenlik parameter is assumed to be immutable by the attacker.
ModificadaMedia (6.4)1.3%—Network Administration Visualized1/5/200616/6/2026
Multiple SQL injection vulnerabilities in the report interface in Network Administration Visualized (NAV) before 3.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (6.8)1.3%—Accounting Receiving AND Inventory Administration Aria3/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in genmessage.php in Accounting Receiving and Inventory Administration (ARIA) 0.99-6 allows remote attackers to inject arbitrary web script or HTML via the Message Field (message parameter).
ModificadaAlta (7.5)1.2%—Mini-nuke CMS23/3/200616/6/2026
Multiple SQL injection vulnerabilities in Mini-Nuke CMS System 1.8.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter in (a) members.asp, the (2) catid parameter in (b) articles.asp and (c) programs.asp, and the (3) id parameter in (d) hpages.asp and (e) forum.asp. NOTE:…
ModificadaMedia (4.3)1.2%—Countersoft Gemini15/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in issue/createissue.aspx in Gemini 2.0 allows remote attackers to inject arbitrary web script or HTML via the rtcDescription$RadEditor1 field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)2.2%💥 ExploitMini-nuke CMS23/2/200616/6/2026
SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: version 2.3 was later reported to be vulnerable as well.
ModificadaAlta (7.5)2.0%💥 ExploitMywebland Minibloggie25/1/200616/6/2026
Vulnerabilidad de inyección de SQL en login.php en miniBloggie 1.0 y anteriores, cuando gpc_magic_quotes está inhabilitado, permite a atacantes remotos ejecutar órdenes SQL de su elección y saltarse la autenticación mediante los parámetros (1) "usernamen" y (2) "password".
ModificadaMedia (5)2.0%—Mini-nuke CMS System13/1/200616/6/2026
membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.
ModificadaAlta (7.5)1.8%💥 ExploitMini-nuke CMS System13/1/200616/6/2026
SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.
ModificadaAlta (7.5)2.6%—SUN Java Communications Services Delegated Administrator7/12/200516/6/2026
Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif.
ModificadaAlta (7.5)3.3%💥 ExploitOliver MAY Athena PHP Website Administration29/11/200516/6/2026
PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter.
ModificadaMedia (4.3)2.3%—Google Mini Search ApplianceGoogle Search Appliance22/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will be executed in the resulting error message.
ModificadaMedia (5)3.6%—Google Mini Search ApplianceGoogle Search Appliance22/11/200516/6/2026
Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to determine the existence of arbitrary files via a relative path from a style sheet directory, then comparing the resulting error messages.
ModificadaAlta (7.5)41%💥 ExploitGoogle Mini Search ApplianceGoogle Search Appliance22/11/200516/6/2026
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2)…
ModificadaMedia (4.3)19%—Google Mini Search ApplianceGoogle Search Appliance22/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a malicious XSLT style sheet.
ModificadaMedia (5)1.8%—Google Mini Search ApplianceGoogle Search Appliance22/11/200516/6/2026
Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports.