Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Classified-software Super MOD System | 16/9/2009 | 16/6/2026 | SQL injection vulnerability in index.php in Super Mod System, when using the 68 Classifieds 3.1 Core System, allows remote attackers to execute arbitrary SQL commands via the s parameter. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Phpclassifiedsscript PHP Classifieds Script | 25/8/2009 | 16/6/2026 | Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Ajsquare AJ Classifieds | 24/8/2009 | 16/6/2026 | AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php. | |
| Modificada | Media (4.3) | 0.85% | — | Xzeroscripts Xzero Community Classifieds | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.85% | — | Xzeroscripts Xzero Community Classifieds | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Xzeroscripts Xzero Community Classifieds | 20/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Classifiedphpscript PHP Open Classifieds Script | 17/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | 68 Classifieds | 17/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (4) searchresults.php and (5) toplistings.php, and (6) member… | |
| Modificada | Media (6.5) | 4.0% | 💥 Exploit | Scriptsfeed Auto Classifieds | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/. | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Scriptsfeed Realtor Classifieds System | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/. | |
| Modificada | Media (6.5) | 3.4% | 💥 Exploit | Phpstore Auto Classifieds | 11/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in cars/cars_images/. | |
| Modificada | Media (6.5) | 3.3% | 💥 Exploit | Phpstore Complete Classifieds | 11/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in classifieds1/yellow_images/. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Preprojects PRE Classified Listings | 3/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject arbitrary web script or HTML via the address parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Preprojects PRE Classified Listings | 3/8/2009 | 16/6/2026 | SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the siteid parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Radscripts Radclassifieds | 27/7/2009 | 16/6/2026 | SQL injection vulnerability in index.php in RadCLASSIFIEDS Gold 2.0 allows remote attackers to execute arbitrary SQL commands via the seller parameter in a search action. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Almondsoft Almond Classifieds | 22/7/2009 | 16/6/2026 | SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Virtuenetz Virtue Classifieds | 9/6/2009 | 16/6/2026 | SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.8) | 2.7% | 💥 Exploit | Unclassified Newsboard | 5/6/2009 | 16/6/2026 | import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. | |
| Modificada | Media (5.1) | 2.0% | 💥 Exploit | Unclassified Newsboard | 5/6/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to (1) read arbitrary recently-modified files via a .. (dot dot) in the GLOBALS[filename] parameter or (2) include and execute… | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Unclassified Newsboard | 5/6/2009 | 16/6/2026 | SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Openautoclassifieds Open Auto Classifieds | 7/4/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Comscripts Quick Classifieds | 30/3/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) locate.php3, (3) search_results.php3, (4) classifieds/index.php3, and (5) classifieds/view.php3; (6) index.php3, (7) manager.php3, (8) pass.php3, (9) remember.php3 (10)… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Bosdev BOS Classifieds | 25/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838. | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | 4u2ges Rapid Classified | 2/3/2009 | 16/6/2026 | Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to cldb.mdb. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Turnkeyforms Local Classifieds | 2/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to inject arbitrary web script or HTML via the r parameter. |