Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1771 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)2.2%—Devellion Cubecart21/8/200616/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en CubeCart 3.0.11 y anteriores permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) file, (2) x, e (3) y en (a) admin/filemanager/preview.php; y el parámetro (4) email en (b) admin/login.php.
ModificadaMedia (4.3)1.3%—Toenda Software Development Toendacms7/8/200616/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en /toendaCMS de toendaCMS stable 1.0.3 y anteriores, y unstable 1.1 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante el parámetro s.
ModificadaMedia (5.8)1.0%—Simian Systems INC Siteforge Collaborative Development Platform12/7/200616/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en index/siteforge-bugs-action/proj.siteforge de SiteForge Collaborative Development Platform 1.0.4 y anteriores permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través de los parámetros (1) _status,…
ModificadaMedia (5.1)5.1%💥 ExploitGeeklogToenda Software Development Toendacms6/7/200616/6/2026
connectors/php/connector.php en el gestor de fichero mcpuk de FCKEditor usado en (1) Geeklog 1.4.0 a la v1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable y anteriores, y posiblemente otros productos, cuando se instala sobre Apache con mod_mime, permite a atacantes remotos subir y ejecutar código PHP de su elección a…
ModificadaMedia (6.8)1.3%—Toenda Software Development Toendacms3/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in content_footer.php in toendaCMS 0.7.0 allows remote attackers to inject arbitrary web scripts or HTML via the print_url variable. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources.
ModificadaMedia (6.4)7.5%💥 ExploitLighthouse Development Squirrelcart19/5/200616/6/2026
PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cart_isp_root parameter.
ModificadaMedia (5.1)3.6%—CAM Development CAM UnzipErik Dienske AbaktRoger Aelbrecht Tzipbuilder9/5/200616/6/2026
Desbordamiento de búfer en (1) TZipBuilder 1.79.03.01, (2) Abakt 0.9.2 y 0.9.3-beta1, (3) CAM UnZip 4.0 y 4.3 y posiblemente en otros productos, permite a atacantes asistidos por usuario ejecutar código arbitrario a través de un archivo ZIP que contiene un archivo con un nombre de archivo largo.
ModificadaAlta (10)4.6%—Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+820/4/200616/6/2026
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
ModificadaAlta (10)11%💥 ExploitAzerbaijan Development Group Azdgvote13/4/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in Azerbaijan Design & Development Group (AZDG) AzDGVote allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter in (1) vote.php, (2) view.php, (3) admin.php, and (4) admin/index.php.
ModificadaMedia (4.3)1.2%—Andries Bruinsma Flexible Development5/4/200616/6/2026
Unspecified vulnerability in main.php in an unspecified "file created by Andries Bruinsma," possibly a FleXiBle Development (FXB) application, allows remote attackers to include and execute arbitrary PHP code. NOTE: this disclosure is extremely vague and has very little information about the specific vulnerability…
ModificadaMedia (5)8.1%💥 ExploitDevellion Cubecart28/2/200616/6/2026
CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified…
ModificadaAlta (7.5)4.8%—Oracle 10G Enterprise Manager Grid ControlOracle Application ServerOracle Collaboration SuiteOracle Database Server+84/2/200616/6/2026
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
ModificadaMedia (4.3)1.4%—Devellion Cubecart18/1/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.7-pl1 allow remote attackers to inject arbitrary web script or HTML via the (3) redir, (4) productId, (5) docId, (6) act, and (7) catId parameters in index.php; and the (8) username field in a login action in index.php. NOTE: the cart.php/redir and…
ModificadaAlta (7.5)1.3%—Idea Development ID OY Timecan CMS7/1/200616/6/2026
SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot be determined if…
ModificadaAlta (7.5)1.3%—Idea Development ID OY Timecan CMS7/1/200616/6/2026
SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot…
ModificadaAlta (7.5)2.4%💥 ExploitDevellion Cubecart3/1/200616/6/2026
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute arbitrary PHP code via a URL in the glob[rootDir] parameter.
ModificadaMedia (6.5)2.1%—Toenda Software Development Toendacms20/12/200516/6/2026
Unrestricted file upload vulnerability in toendaCMS before 0.6.2 Stable allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in data/images/albums.
ModificadaMedia (4.3)1.2%—Quicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.
ModificadaAlta (7.5)1.2%💥 ExploitQuicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
ModificadaAlta (7.5)1.2%—Toenda Software Development Toendacms20/12/200516/6/2026
SQL injection vulnerability in index.php in toendaCMS 0.6.2.1, when configured to use a SQL database, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.4%—Toenda Software Development Toendacms16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in toendaCMS before 0.7 Beta allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)2.7%💥 ExploitScriptdevelopers.net Netclassifieds3/12/200516/6/2026
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition 1.0.1, Professional Edition 1.5.1, Standard Edition 1.9.6.3, and Free Edition 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter in (a) ViewCat.php and (b) gallery.php, and the (2) ItemNum parameter in (c)…
ModificadaMedia (5)1.4%—Toenda Software Development Toendacms16/11/200516/6/2026
toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.
ModificadaMedia (5)6.3%💥 ExploitToenda Software Development Toendacms16/11/200516/6/2026
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.
ModificadaMedia (4.3)2.2%💥 ExploitDevellion Cubecart5/10/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) the searchStr parameter in a viewCat action to index.php. Note: vectors (1) and (2) were later reported to affect…