Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.8% | 💥 Exploit | Enthrallweb Eclassifieds | 29/12/2006 | 16/6/2026 | myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Enthrallweb Eclassifieds | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and the (6) sid parameter to (c) dirSub.asp. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Deltascripts PHP Classifieds | 10/11/2006 | 16/6/2026 | SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Deltascripts PHP Classifieds | 26/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in functions.php in DeltaScripts PHP Classifieds 7.1 allows remote attackers to execute arbitrary PHP code via a URL in the set_path parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Phpoutsourcing Noahs Classifieds | 16/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PhpOutsourcing Noah's Classifieds 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the frommethod parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Deltascripts PHP Classifieds | 10/10/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Joomla Classifieds ComponentJoomla COM Classifieds | 27/9/2006 | 16/6/2026 | Unspecified vulnerability in Classifieds (com_classifieds) component 1.3 and earlier for Joomla! has unspecified impact and attack vectors. | |
| Modificada | Media (5.1) | 1.9% | 💥 Exploit | Geodesicsolutions Geoauctions PremierGeodesicsolutions Geoclassifieds Basic | 25/7/2006 | 16/6/2026 | SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter. | |
| Modificada | Alta (7.5) | 4.3% | — | Bosdev Bosclassifieds Classified ADS | 12/7/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via a URL in the insPath parameter to (1) index.php, (2) recent.php, (3) account.php, (4) classified.php, or (5) search.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Deltascripts PHP Classifieds | 30/6/2006 | 16/6/2026 | SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter. | |
| Modificada | Media (6.8) | 1.5% | — | Deltascripts PHP Classifieds | 30/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php. | |
| Modificada | Media (4.3) | 1.2% | — | Cescripts CAR Classifieds | 19/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Car Classifieds allows remote attackers to inject arbitrary web script or HTML via the make_id parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Locazolist Classifieds | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Deltascripts PHP Classifieds | 30/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter. | |
| Modificada | Media (6.4) | 1.6% | — | Phpoutsourcing Noahs Classifieds | 21/3/2006 | 16/6/2026 | Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error message. | |
| Modificada | Media (6.8) | 1.4% | — | Phpoutsourcing Noahs Classifieds | 21/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter. | |
| Modificada | Media (5) | 1.5% | — | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Deltascripts PHP Classifieds | 15/2/2006 | 16/6/2026 | SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Almondsoft Almond ClassifiedsAI | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds 5.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Locazolist Classifieds | 13/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Scriptdevelopers.net Netclassifieds | 3/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c)… |