Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
173 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Consulo IP Alarm | 19/10/2014 | 17/6/2026 | The IP Alarm (aka com.cosesy.gadget.alarm) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | WP Consultant Project WP Consultant | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/admin_show_dialogs.php in the WP Consultant plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the dialog_id parameter. | |
| Modificada | Baja (2.1) | 0.94% | — | Freelance-it-consultant EU Cookie Compliance | 29/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values. | |
| Modificada | Media (5) | 1.3% | — | Longwaveconsulting Ubercart Securetrading Payment Method Module | 31/10/2012 | 16/6/2026 | The Ubercart SecureTrading Payment Method module 6.x for Drupal does not properly verify payment notification information, which allows remote attackers to purchase an item without paying via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.94% | — | Tag1consulting Support Timer | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Support Timer module 6.x-1.x before 6.x-1.4 for Drupal allows remote authenticated users with the "track time spent" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 1.0% | — | Tag1consulting Support | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Support Ticketing System module 6.x-1.x before 6.x-1.7 for Drupal allows remote authenticated users with the "administer support projects" permission to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.87% | — | Hashmarkconsulting Controlpanel | 25/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Parkviewconsultants COM Simplefaq | 12/2/2010 | 16/6/2026 | SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action to index.php. | |
| Modificada | Media (4.3) | 1.5% | — | Spacetag LacoodastSystem Consultants LA Cooda WIZ | 27/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences. | |
| Modificada | Alta (10) | 2.7% | — | Spacetag LacoodastSystem Consultants LA Cooda WIZ | 27/8/2008 | 16/6/2026 | Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scripts, and delete files, read files, and possibly have unknown other impact. | |
| Modificada | Media (6) | 0.56% | — | Spacetag LacoodastSystem Consultants LA Cooda WIZ | 27/8/2008 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (a) change passwords or (b) change configurations. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | PHP Nuke Basis Consultant Book Catalog | 7/8/2008 | 16/6/2026 | SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to modules.php. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | MamboParkview Consultants Simplefaq | 21/8/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo. | |
| Modificada | Media (4.3) | 1.3% | — | Boesch It-consulting Progsys | 27/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in heading.php in Boesch ProgSys 0.151 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php, and unspecified vectors related to certain other files. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Boesch It-consulting Simpnews | 26/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Boesch It-consulting Progsys | 23/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter. | |
| Modificada | Media (5) | 2.2% | — | Tamarack Consulting Tamarack Mmsd | 29/7/2006 | 16/6/2026 | Tamarack MMSd before 7.992 allows remote attackers to cause a denial of service (crash) via malformed RFC1006 (OSI over TCP/IP) packets. | |
| Modificada | Alta (10) | 3.6% | — | Himpfen Consulting PHP Simplenews | 19/3/2006 | 16/6/2026 | admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Curtis Specialty Consulting Iispop | 31/12/2002 | 16/6/2026 | Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via a long request to the POP3 port (TCP port 110). | |
| Modificada | Alta (7.5) | 4.6% | — | Peaceworks Computer Consulting Phormation | 2/10/2001 | 16/6/2026 | Phormation PHP script 0.9.1 and earlier allows remote attackers to execute arbitrary code by including files from remote web sites, using an HTTP request that modifies the phormationdir variable. | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Hassan Consulting Shopping Cart | 8/9/2001 | 16/6/2026 | shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter. | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Hassan Consulting Shopping Cart | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read arbitrary files via a .. (dot dot) attack on the page parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Baron Consulting Group Websitetool | 1/2/2000 | 16/6/2026 | The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. |