Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 8.4% | 💥 Exploit | Ajsquare Zeuscart | 10/3/2015 | 17/6/2026 | ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function. | |
| Modificada | Media (5) | 0.98% | — | Square Enix CO LTD Kaku SAN SEI Million Aruthur | 5/12/2014 | 17/6/2026 | SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain privileges via a crafted application. | |
| Modificada | Media (5.4) | 0.27% | — | Nuphoto Nusquare | 22/9/2014 | 17/6/2026 | The nuSquare (aka tw.com.nuphoto.nusquare) application 1.0.78 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 46% | 💥 Exploit | Square Squash | 27/5/2014 | 16/6/2026 | The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb. | |
| Modificada | Media (6.8) | 0.95% | — | Crunchify Foursquare-checkins | 26/4/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Ajsquare AJ Auction Pro-oopd | 25/8/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via the txtkeyword parameter in a search action. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ajsquare AJ Article | 30/7/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ajsquare AJ Hyip | 30/7/2010 | 16/6/2026 | SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ajsquare AJ Hyip | 30/7/2010 | 16/6/2026 | SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ajsquare AJ Shopping Cart | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Ajsquare AJ Auction Pro-oopd | 16/9/2009 | 16/6/2026 | SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Ajsquare AJ Article | 24/8/2009 | 16/6/2026 | AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php,… | |
| Modificada | Media (6.4) | 2.2% | 💥 Exploit | Ajsquare Free Polling Script | 24/8/2009 | 16/6/2026 | AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.4) | 2.6% | 💥 Exploit | Ajsquare Free Polling Script | 24/8/2009 | 16/6/2026 | AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Ajsquare Free Polling Script | 24/8/2009 | 16/6/2026 | SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Ajsquare AJ Classifieds | 24/8/2009 | 16/6/2026 | AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Ajsquare AJ Matrix DNA | 17/8/2009 | 16/6/2026 | SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | AJ Square AJ Auction | 13/8/2009 | 16/6/2026 | AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authentication via a direct request to admin/user.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | AJ Square AJ Auction | 13/8/2009 | 16/6/2026 | AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php,… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ajsquare AJ Article | 14/4/2009 | 16/6/2026 | SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field). | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | AJ Square AJ Auction | 6/3/2009 | 16/6/2026 | SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | AJ Square AJ Auction | 28/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via the product parameter. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | AJ Square AJ Auction | 28/1/2009 | 16/6/2026 | SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute arbitrary SQL commands via the seller_id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | AJ Square Zeuscart | 24/11/2008 | 16/6/2026 | SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | AJ Square AJ Article | 24/11/2008 | 16/6/2026 | SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action. |