Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.0% | — | Xigla Absolute Banner Manager | 18/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute Banner Manager XE 2.0 allow remote authenticated administrators to inject arbitrary web script or HTML via the text parameter in (1) searchbanners.asp and (2) listadvertisers.asp, and other unspecified fields. NOTE: some of these details are… | |
| Modificada | Media (6.5) | 1.2% | — | Xigla Absolute Banner Manager | 18/6/2008 | 16/6/2026 | SQL injection vulnerability in searchbanners.asp in Xigla Absolute Banner Manager XE 2.0 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Medialand Rotabanner Local | 10/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in account/index.html in RotaBanner Local 3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) drop parameter. | |
| Modificada | Media (5) | 1.3% | — | PHP Mysql Banner Exchange | 21/12/2007 | 16/6/2026 | PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database information via a direct request to inc/lib.inc. | |
| Modificada | Alta (7.5) | 1.1% | — | Xigla Absolute Banner Manager.net | 10/12/2007 | 16/6/2026 | SQL injection vulnerability in abm.aspx in Xigla Absolute Banner Manager .NET 4.0 allows remote attackers to execute arbitrary SQL commands via the z parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Jiro Banner System | 22/11/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System (JBS) 2.0, and possibly JiRo's Upload Manager (aka JiRo's Upload System or JUS), allow remote attackers to execute arbitrary SQL commands via the (1) Username (aka Login or Email) or (2) Password field. | |
| Modificada | Media (6.5) | 0.87% | 💥 Exploit | Softbizscripts Banner Exchange Network Script | 15/11/2007 | 16/6/2026 | SQL injection vulnerability in campaign_stats.php in Softbiz Banner Exchange Network Script 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | PHP WEB Scripts Easy Banner PRO | 11/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | PHP WEB Scripts Easy Banner Free | 5/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter. | |
| Modificada | Media (6.8) | 2.9% | 💥 Exploit | Mambo Multibanners | 25/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Analizada | Media (4.3) | 1.8% | 💥 Exploit | Softbizscripts Banner Exchange Script | 18/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php,… | |
| Modificada | Media (5.8) | 1.5% | — | Native Solutions THE Banner Engine | 11/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in The Banner Engine (tbe) 4.0 allow remote attackers to execute arbitrary web script or HTML via the (1) text parameter in a search action to (a) top.php, and the (2) adminpass or (3) adminlogin parameter to (b) signup.php. | |
| Modificada | Media (5.1) | 2.1% | — | Eschew.net Phpbannerexchange | 19/6/2006 | 16/6/2026 | Interpretation conflict in resetpw.php in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via an email parameter containing a null (%00) character after a valid e-mail address, which passes the validation check in the eregi PHP command. NOTE: it could be argued that this… | |
| Modificada | Alta (7.5) | 1.5% | — | Eschew.net Phpbannerexchange | 19/6/2006 | 16/6/2026 | SQL injection vulnerability in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via the (1) login parameter in (a) client/stats.php and (b) admin/stats.php, or the (2) pass parameter in client/stats.php. | |
| Modificada | Alta (7.5) | 4.0% | — | Duware Dubanner Project Duware Dubanner | 17/5/2006 | 16/6/2026 | add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enforcement that can be bypassed. NOTE: some of these details are obtained from third party information, since the raw source is vague. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Perlcoders Group Bannerfarm | 20/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters. | |
| Modificada | Baja (2.6) | 1.8% | 💥 Exploit | Aweb Banner Generator | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Aweb Banner Generator 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the banner parameter in view mode. | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Jiro Banner System | 14/3/2006 | 16/6/2026 | JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account. | |
| Modificada | Media (5) | 2.8% | — | Eschew.net Phpbannerexchange | 14/3/2006 | 16/6/2026 | Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot dot) in the email parameter during a "Recover password" operation (recoverpw.php). | |
| Modificada | Media (4.3) | 1.2% | — | Native Solutions TBE Banner Engine | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability. | |
| Modificada | Alta (10) | 5.4% | — | Bannerwheel | 31/12/2002 | 16/6/2026 | Buffer overflow in badmin.c in BannerWheel 1.0 allows remote attackers to execute arbitrary code via a long rcmd command. | |
| Modificada | Media (5) | 1.0% | — | JOE Depasquale Bannermatic | 31/12/2002 | 16/6/2026 | Bannermatic 1, 2, and 3 stores the (1) ban.log, (2) ban.bak, (3) ban.dat and (4) banmat.pwd data files under the web document root with insufficient access control, which allows attackers to obtain sensitive information via a direct request for the files. | |
| Modificada | Media (5.1) | 2.4% | — | Selena SOL Webbanner | 2/2/2000 | 16/6/2026 | Selena Sol WebBanner 4.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack. |