Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 2.7% | 💥 Exploit | Wikepage | 28/8/2006 | 16/6/2026 | Directory traversal vulnerability in index.php for Wikepage 2006.2a Opus 10 allows remote attackers to include arbitrary local files via the lng parameter, as demonstrated by inserting PHP code into a log file. | |
| Modificada | Crítica (9.8) | 1.8% | — | Mambo MTG Myhomepage Component | 21/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) install.lmtg_homepage.php and (2) mtg_homepage.php. NOTE: this issue has been disputed by a… | |
| Modificada | Baja (2.6) | 1.3% | — | 4homepages 4images | 25/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php. | |
| Modificada | Alta (7.5) | 2.8% | — | HP CompaqhttpserverHP System Management Homepage | 13/4/2006 | 16/6/2026 | HP System Management Homepage (SMH) 2.1.3.132, when running on CompaqHTTPServer/9.9 on Windows, Linux, or Tru64 UNIX, and when "Trust by Certificates" is not enabled, allows remote attackers to bypass authentication via a crafted URL. | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Htmljunction Ezhomepagepro | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in EZHomepagePro 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) adid or (2) aname parameter in (a) common/email.asp, (b) users/users_search.asp, or (c) users/users_profiles.asp; (3) page parameter in (d)… | |
| Modificada | Media (5) | 5.2% | — | HP System Management Homepage | 7/3/2006 | 16/6/2026 | Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote attackers to access certain files via unspecified vectors. | |
| Modificada | Media (4.3) | 1.8% | — | MY Little Homepage MY Little Guestbook | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guestbook.php in my little homepage my little guestbook, as last modified in March 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | MY Little Homepage MY Little Weblog | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags. | |
| Modificada | Media (4.3) | 1.8% | — | MY Little Homepage MY Little Forum | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the bbcode function in functions.php in my little homepage my little forum, as last modified in June 2005, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | MY Little Homepage MY Little Forum | 24/9/2005 | 16/6/2026 | SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field. | |
| Modificada | Alta (7.5) | 4.9% | — | Secure Reality Phpsecurepages | 13/7/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | All4www-homepagecreator | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in All4WWW-Homepagecreator 1.0a allows remote attackers to execute arbitrary PHP code by modifying the site parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Easy Scripts Archive Advanced Easy Homepage CreatorEasy Scripts Archive Easy Homepage Creator | 11/4/2003 | 16/6/2026 | The print_html_to_file function in edit.cgi for Easy Homepage Creator 1.0 does not check user credentials, which allows remote attackers to modify home pages of other users. | |
| Modificada | Alta (7.5) | 1.9% | — | Secure Reality Phpsecurepages | 7/2/2001 | 16/6/2026 | PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | IBM Homepageprint | 2/11/1999 | 16/6/2026 | Buffer overflow in IBM HomePagePrint 1.0.7 for Windows98J allows a malicious Web site to execute arbitrary code on a viewer's system via a long IMG_SRC HTML tag. |