Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
165 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Bdigital WEB Solutions Webstudio Ecatalogue | 1/12/2008 | 16/6/2026 | SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL commands via the pageid parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Kkeim Kmita Catalogue | 13/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | PHP Nuke Basis Consultant Book Catalog | 7/8/2008 | 16/6/2026 | SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mamboserver Catalogshop | 4/2/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | |
| Modificada | Alta (7.5) | 1.2% | — | ASP Product Catalog | 5/10/2007 | 16/6/2026 | SQL injection vulnerability in catalog.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter and possibly other parameters. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Chris MAC Gimescripts Shopping Catalog | 15/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the custom parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Mambo Catalogshop Component | 21/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in catalogshop.php in the CatalogShop component for Mambo (com_catalogshop) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (6.4) | 1.7% | — | Open Searchable Image Catalogue | 1/6/2006 | 16/6/2026 | SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary SQL commands via multiple vectors, as demonstrated by the (1) type parameter in adminfunctions.php and the (2) catalogue_id parameter in… | |
| Modificada | Media (4.3) | 1.7% | — | Open Searchable Image Catalogue | 1/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before 0.7.0.1 allows remote attackers to inject arbitrary web scripts or HTML via failed SQL queries, which is reflected in an error message. | |
| Modificada | Media (6.4) | 1.3% | — | Open Searchable Image Catalogue | 1/6/2006 | 16/6/2026 | SQL injection vulnerability in search.php in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary SQL commands via the (1) txtCustomField and (2) CustomFieldID array parameters. | |
| Modificada | Media (4.3) | 1.3% | — | Open Searchable Image Catalogue | 1/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote attackers to inject arbitrary web scripts or HTML via the item_list parameter in search.php. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (4.3) | 1.3% | — | Sitebeater MP3 Catalog | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Search.asp in SiteBeater MP3 Catalog 2.03 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Media (4.3) | 1.4% | — | Actinic Catalog | 31/12/2002 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Actinic Catalog 4.7.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string argument to certain .pl files, (2) the REFPAGE parameter to ca000007.pl, (3) PRODREF parameter to ss000007.pl, or (4) hop parameter to ca000001.pl. | |
| Modificada | Alta (7.5) | 2.3% | — | Virtualcart Virtualcatalog | 18/10/2001 | 16/6/2026 | CatalogMgr.pl in VirtualCatalog (incorrectly claimed to be in VirtualCart) allows remote attackers to execute arbitrary code via the template parameter. |