Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

173 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.27%—Consulo IP Alarm19/10/201417/6/2026
The IP Alarm (aka com.cosesy.gadget.alarm) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.6%—WP Consultant Project WP Consultant2/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in admin/admin_show_dialogs.php in the WP Consultant plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the dialog_id parameter.
ModificadaBaja (2.1)0.94%—Freelance-it-consultant EU Cookie Compliance29/4/201417/6/2026
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values.
ModificadaMedia (5)1.3%—Longwaveconsulting Ubercart Securetrading Payment Method Module31/10/201216/6/2026
The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors.
ModificadaBaja (2.1)0.94%—Tag1consulting Support Timer20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Support Timer module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "track time spent" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (2.1)1.0%—Tag1consulting Support20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.87%—Hashmarkconsulting Controlpanel25/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)0.97%💥 ExploitParkviewconsultants COM Simplefaq12/2/201016/6/2026
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action to index.php.
ModificadaMedia (4.3)1.5%—Spacetag LacoodastSystem Consultants LA Cooda WIZ27/8/200816/6/2026
Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences.
ModificadaAlta (10)2.7%—Spacetag LacoodastSystem Consultants LA Cooda WIZ27/8/200816/6/2026
Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scripts, and delete files, read files, and possibly have unknown other impact.
ModificadaMedia (6)0.56%—Spacetag LacoodastSystem Consultants LA Cooda WIZ27/8/200816/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (a) change passwords or (b) change configurations.
ModificadaAlta (7.5)1.1%💥 ExploitPHP Nuke Basis Consultant Book Catalog7/8/200816/6/2026
SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php.
ModificadaAlta (7.5)2.4%💥 ExploitMamboParkview Consultants Simplefaq21/8/200716/6/2026
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.
ModificadaMedia (4.3)1.3%—Boesch It-consulting Progsys27/10/200616/6/2026
Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.7%💥 ExploitBoesch It-consulting Simpnews26/10/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are…
ModificadaAlta (7.5)2.5%💥 ExploitBoesch It-consulting Progsys23/9/200616/6/2026
PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter.
ModificadaMedia (5)2.2%—Tamarack Consulting Tamarack Mmsd29/7/200616/6/2026
Tamarack MMSd before 7.992 allows remote attackers to cause a denial of service (crash) via malformed RFC1006 (OSI over TCP/IP) packets.
ModificadaAlta (10)3.6%—Himpfen Consulting PHP Simplenews19/3/200616/6/2026
admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie.
ModificadaMedia (5)2.9%💥 ExploitCurtis Specialty Consulting Iispop31/12/200216/6/2026
Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110).
ModificadaAlta (7.5)4.6%—Peaceworks Computer Consulting Phormation2/10/200116/6/2026
Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable.
ModificadaAlta (7.5)3.9%💥 ExploitHassan Consulting Shopping Cart8/9/200116/6/2026
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.
ModificadaMedia (5)8.1%💥 ExploitHassan Consulting Shopping Cart19/12/200023/9/2026
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter.
ModificadaAlta (7.5)2.0%—Baron Consulting Group Websitetool1/2/200016/6/2026
The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
Orbitaley — Vulnerabilidades