Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

254 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.00%💥 ExploitClassified-software Super MOD System16/9/200916/6/2026
SQL injection vulnerability in index.php in Super Mod System, when using the 68 Classifieds 3.1 Core System, allows remote attackers to execute arbitrary SQL commands via the s parameter.
ModificadaMedia (5)7.6%💥 ExploitPhpclassifiedsscript PHP Classifieds Script25/8/200916/6/2026
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.
ModificadaAlta (7.5)2.8%💥 ExploitAjsquare AJ Classifieds24/8/200916/6/2026
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
ModificadaMedia (4.3)0.85%—Xzeroscripts Xzero Community Classifieds21/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)0.85%—Xzeroscripts Xzero Community Classifieds21/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.5%💥 ExploitXzeroscripts Xzero Community Classifieds20/8/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter.
ModificadaMedia (4.3)1.3%—Classifiedphpscript PHP Open Classifieds Script17/8/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php.
ModificadaMedia (4.3)2.2%💥 Exploit68 Classifieds17/8/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (4) searchresults.php and (5) toplistings.php, and (6) member…
ModificadaMedia (6.5)4.0%💥 ExploitScriptsfeed Auto Classifieds12/8/200916/6/2026
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/.
ModificadaMedia (6.5)3.9%💥 ExploitScriptsfeed Realtor Classifieds System12/8/200916/6/2026
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.
ModificadaMedia (6.5)3.4%💥 ExploitPhpstore Auto Classifieds11/8/200916/6/2026
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in cars/cars_images/.
ModificadaMedia (6.5)3.3%💥 ExploitPhpstore Complete Classifieds11/8/200916/6/2026
Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in classifieds1/yellow_images/.
ModificadaMedia (4.3)1.5%💥 ExploitPreprojects PRE Classified Listings3/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML via the address parameter.
ModificadaAlta (7.5)0.99%💥 ExploitPreprojects PRE Classified Listings3/8/200916/6/2026
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter.
ModificadaAlta (7.5)1.00%💥 ExploitRadscripts Radclassifieds27/7/200916/6/2026
SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action.
ModificadaAlta (7.5)0.91%💥 ExploitAlmondsoft Almond Classifieds22/7/200916/6/2026
SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
ModificadaAlta (7.5)1.0%💥 ExploitVirtuenetz Virtue Classifieds9/6/200916/6/2026
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaAlta (7.8)2.7%💥 ExploitUnclassified Newsboard5/6/200916/6/2026
import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
ModificadaMedia (5.1)2.0%💥 ExploitUnclassified Newsboard5/6/200916/6/2026
Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to (1) read arbitrary recently-modified files via a .. (dot dot) in the GLOBALS[filename] parameter or (2) include and execute…
ModificadaAlta (7.5)0.99%💥 ExploitUnclassified Newsboard5/6/200916/6/2026
SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686.
ModificadaAlta (7.5)1.1%💥 ExploitOpenautoclassifieds Open Auto Classifieds7/4/200916/6/2026
Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php.
ModificadaAlta (7.5)2.5%💥 ExploitComscripts Quick Classifieds30/3/200916/6/2026
Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) locate.php3, (3) search_results.php3, (4) classifieds/index.php3, and (5) classifieds/view.php3; (6) index.php3, (7) manager.php3, (8) pass.php3, (9) remember.php3 (10)…
ModificadaAlta (7.5)0.97%💥 ExploitBosdev BOS Classifieds25/3/200916/6/2026
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838.
ModificadaMedia (5)2.2%💥 Exploit4u2ges Rapid Classified2/3/200916/6/2026
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cldb.mdb.
ModificadaMedia (4.3)1.5%💥 ExploitTurnkeyforms Local Classifieds2/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter.
Orbitaley — Vulnerabilidades