Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)8.4%💥 ExploitAjsquare Zeuscart10/3/201517/6/2026
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.
ModificadaMedia (5)0.98%—Square Enix CO LTD Kaku SAN SEI Million Aruthur5/12/201417/6/2026
SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain privileges via a crafted application.
ModificadaMedia (5.4)0.27%—Nuphoto Nusquare22/9/201417/6/2026
The nuSquare (aka tw.com.nuphoto.nusquare) application 1.0.78 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)46%💥 ExploitSquare Squash27/5/201416/6/2026
The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb.
ModificadaMedia (6.8)0.95%—Crunchify Foursquare-checkins26/4/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the FourSquare Checkins plugin before 1.3 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
ModificadaMedia (4.3)1.5%💥 ExploitAjsquare AJ Auction Pro-oopd25/8/201016/6/2026
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via the txtkeyword parameter in a search action.
ModificadaMedia (4.3)1.7%💥 ExploitAjsquare AJ Article30/7/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an…
ModificadaAlta (7.5)0.97%💥 ExploitAjsquare AJ Hyip30/7/201016/6/2026
SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitAjsquare AJ Hyip30/7/201016/6/2026
SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitAjsquare AJ Shopping Cart12/5/201016/6/2026
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action.
ModificadaAlta (7.5)0.99%💥 ExploitAjsquare AJ Auction Pro-oopd16/9/200916/6/2026
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)2.5%💥 ExploitAjsquare AJ Article24/8/200916/6/2026
AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2) articles.php, (3) articlesuspend.php, (4) site.php, (5) statistics.php, (6) mail.php, (7) category.php, (8) subcategory.php, (9) changepassword.php, (10) polling.php,…
ModificadaMedia (6.4)2.2%💥 ExploitAjsquare Free Polling Script24/8/200916/6/2026
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/newpoll.php, a different vector than CVE-2008-7045. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.4)2.6%💥 ExploitAjsquare Free Polling Script24/8/200916/6/2026
AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to admin/resetvote.php.
ModificadaAlta (7.5)1.00%💥 ExploitAjsquare Free Polling Script24/8/200916/6/2026
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to execute arbitrary SQL commands via the ques parameter.
ModificadaAlta (7.5)2.8%💥 ExploitAjsquare AJ Classifieds24/8/200916/6/2026
AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.
ModificadaAlta (7.5)0.99%💥 ExploitAjsquare AJ Matrix DNA17/8/200916/6/2026
SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action.
ModificadaAlta (7.5)2.5%💥 ExploitAJ Square AJ Auction13/8/200916/6/2026
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authentication via a direct request to admin/user.php.
ModificadaAlta (7.5)2.6%💥 ExploitAJ Square AJ Auction13/8/200916/6/2026
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php,…
ModificadaAlta (7.5)0.97%💥 ExploitAjsquare AJ Article14/4/200916/6/2026
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL commands via the txtName parameter (aka the username field).
ModificadaAlta (7.5)1.00%💥 ExploitAJ Square AJ Auction6/3/200916/6/2026
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
ModificadaMedia (4.3)1.2%💥 ExploitAJ Square AJ Auction28/1/200916/6/2026
Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via the product parameter.
ModificadaAlta (7.5)0.93%💥 ExploitAJ Square AJ Auction28/1/200916/6/2026
SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute arbitrary SQL commands via the seller_id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitAJ Square Zeuscart24/11/200816/6/2026
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)1.00%💥 ExploitAJ Square AJ Article24/11/200816/6/2026
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a search detail action.