Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Turnkeyforms Local Classifieds | 2/3/2009 | 16/6/2026 | SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitrary SQL commands via the r parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Softbizscripts Classifieds Script | 27/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio parameter to gallery.php, (4) msg parameter to lostpassword.php,… | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Softbizscripts Classifieds Script | 26/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Turnkeyforms Local Classifieds | 26/2/2009 | 16/6/2026 | TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/admin.php. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Preprojects PRE Classified Listings | 20/2/2009 | 16/6/2026 | Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) adminid cookies to "admin". | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Sepcity Classified ADS | 17/2/2009 | 16/6/2026 | SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Sepcity Classified ADS | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Dmxready Classified Listings Manager | 5/2/2009 | 16/6/2026 | SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (5) | 1.1% | — | Preprojects PRE Classified Listings | 4/2/2009 | 16/6/2026 | PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | WEB Scribble Solutions Webclassifieds | 2/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Web Scribble Solutions webClassifieds 2005 allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) password fields in a sign_in action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Deltascripts PHP Classifieds | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka admin field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Deltascripts PHP Classifieds | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the siteid parameter, a different vector than CVE-2006-5828. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Yourfreeworld Classifieds Blaster Script | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Yourfreeworld Classifieds Hosting Script | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Pozscripts Classified Auctions Script | 28/10/2008 | 16/6/2026 | SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Spice Classifieds | 11/9/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands via the cat_path parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Yourfreeworld Classifieds | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Pozscripts Classified ADS | 13/8/2008 | 16/6/2026 | SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3673. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Pozscripts Classified ADS | 13/8/2008 | 16/6/2026 | SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3672. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mojoscripts Mojoclassifieds | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mybizz-classifieds | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Carscripts Classifieds | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Boatscripts Classifieds | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL commands via the type parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Phpclassifiedsscript PHP Classifieds Script | 27/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | 68 Classifieds | 19/5/2008 | 16/6/2026 | SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter. |