Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2776▲ 17 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1454 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Mywebland Myevent11/8/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en viewevent.php en myWebland myEvent 1.x permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro myevent_path, un vector distinto de CVE-2006-4040. NOTA: la procedencia de esta información es desconocida; los detalles se han…
ModificadaAlta (7.5)4.0%💥 ExploitWeb-scripts Visual Events Calendar10/8/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en calendar.php de Visual Events Calendar 1.1 permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro cfg_dir.
ModificadaAlta (7.5)3.5%💥 ExploitMywebland Myevent9/8/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en myevent.php en myWebland MyEvent 1.3 y anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro myevent_path.
ModificadaAlta (7.5)2.1%—Softcomplex PHP Event Calendar21/7/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en calendar.php de SoftComplex PHP Event Calendar 1.4 permite a atacantes remotos ejecutar código PHP de su elección mediante un URL en el parámetro path_to_calendar, el cual sobrescribe la variable $path_to_calendar de una llamada a la función extract.
ModificadaMedia (6.8)1.8%💥 ExploitCescripts Event Registration 2checkoutCescripts Event Registration CorporateCescripts Event Registration PaypalCescripts Event Registration Rsvp16/6/200616/6/2026
Vulnerabilidad de ejecución de comandos en sitios cruzados (Cross-site scripting (XSS)) en el Registro de Eventos (Event Registration) que permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) event_id para ver-evento-details.php o (2) el parámetro select_events para…
ModificadaMedia (5.8)1.3%—Faktorystudios Easyevent9/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in easyEvent 1.2 allows remote attackers to inject arbitrary web script or HTML via the curr_year parameter.
ModificadaMedia (5)5.9%💥 ExploitArtmedic Webdesign Artmedic Event1/5/200616/6/2026
PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter.
ModificadaAlta (7.5)1.2%—Mywebland Myevent20/4/200616/6/2026
Multiple SQL injection vulnerabilities in myEvent 1.x allow remote attackers to inject arbitrary SQL commands via the event_id parameter to (1) addevent.php or (2) del.php or (3) event_desc parameter to addevent.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaBaja (2.6)1.2%—Mywebland Myevent20/4/200616/6/2026
Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)4.4%—Mywebland Myevent20/4/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in myWebland myEvent 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter in (1) event.php and (2) initialize.php. NOTE: vector 2 was later reported to affect 1.4 as well.
ModificadaBaja (2.6)1.2%—Updi Network Enterprise AT1 Event Publisher17/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in tablepublisher.cgi in UPDI Network Enterprise @1 Table Publisher 2006-03-23 allows remote attackers to inject arbitrary web script or HTML via the Title of Table field.
ModificadaMedia (4.3)1.2%—Upoint AT1 Event Publisher15/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_admin.htm and (b) eventpublisher_usersubmit.htm.
ModificadaMedia (5)1.4%—Upoint AT1 Event Publisher15/4/200616/6/2026
UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.
ModificadaAlta (7.5)1.4%—Maian Events21/3/200616/6/2026
SQL injection vulnerability in events.php in Maian Events 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.
ModificadaBaja (3.5)1.1%—Softcomplex PHP Event Calendar13/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php. NOTE: while this issue was originally…
ModificadaMedia (5.8)2.9%💥 ExploitMysql Eventum31/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php.
ModificadaMedia (6.4)2.0%💥 ExploitMysql Eventum31/12/200516/6/2026
Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or…
ModificadaAlta (7.5)1.2%💥 Exploit88script Event Calendar1/12/200516/6/2026
SQL injection vulnerability in index.php in 88Script's Event Calendar 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter.
ModificadaAlta (7.5)5.6%—Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+1530/11/200516/6/2026
Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.
ModificadaAlta (7.5)1.3%—Wwweb Concepts Events System5/6/200516/6/2026
SQL injection vulnerability in login.asp for WWWeb Concepts Events System 1.0 allows remote attackers to execute arbitrary SQL commands via the password.
ModificadaMedia (4.6)0.59%—HP Openview Event Correlation Services3/5/200516/6/2026
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.
ModificadaAlta (7.5)1.3%—Phpnuke Event CalendarAI31/12/200416/6/2026
SQL injection vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the (1) eid or (2) cid parameters.
ModificadaMedia (5)1.5%—ROB Sutton Php-nuke Event Calendar31/12/200416/6/2026
The Event Calendar module 2.13 for PHP-Nuke allows remote attackers to gain sensitive information via an HTTP request to (1) config.php, (2) index.php, or (3) submit.php, which reveal the full path in an error message.
ModificadaMedia (4.3)1.4%—ROB Sutton Php-nuke Event Calendar31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in the Event Calendar module 2.13 for PHP-Nuke allows remote attackers to execute arbitrary web script via the (1) type, (2) day, (3) month, or (4) year parameters in a Preview operation, or (5) event comments.
AnalizadaMedia (5)80%💥 ExploitJuniper JunosMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98se+818/8/20049/10/2026
TCP, cuando se usa un tamaño de ventana de transmisión grande, hace más fácil a atacantes remotos adivinar números de secuencia y causar una denegación de servicio (pérdida de la conexión) en conexiones TCP persistentes inyectando repetidamente un paquete TCP RST, especialmente en protocolos que usan conexiones de…