Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | BIG Webmaster Guestbook Script | 5/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in addguest.cgi in Big Webmaster Guestbook Script 1.02 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) site, (3) city, (4) state, (5) country, and possibly (6) name fields, which are viewed via viewguest.cgi. | |
| Modificada | Media (4.3) | 1.2% | — | Scriptsez Cute Guestbook | 5/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Scriptsez Cute Guestbook 20060211 allows remote attackers to inject arbitrary web script or HTML via the Comments field when signing the guestbook. | |
| Modificada | Alta (7.5) | 8.3% | 💥 Exploit | Phpbb Group Phpbb Advanced Guestbook | 3/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter. | |
| Modificada | Media (6.4) | 1.6% | — | Stadtaus Guestbook Script | 3/5/2006 | 16/6/2026 | Dynamic variable evaluation vulnerability in index.php in Stadtaus Guestbook Script 1.7 and earlier, when register_globals is enabled, allows remote attackers to modify arbitrary program variables via parameters, which are evaluated as PHP variable variables, as demonstrated by performing PHP remote file inclusion… | |
| Modificada | Media (4.3) | 1.2% | — | Community Architect Guestbook | 25/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cgi-bin/guest in Community Architect Guestbook allows remote attackers to inject arbitrary web script or HTML by signing the guestbook, which is displayed by fsguestbook.html. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | JAX Scripts JAX Guestbook | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Baja (1.2) | 0.60% | — | Phpguestbook | 18/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter. | |
| Modificada | Alta (7.6) | 1.8% | 💥 Exploit | Design Nation Dnguestbook | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Matt Wright Guestbook | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Comments fields when posting a message. | |
| Modificada | Media (4.3) | 1.2% | — | Matt Wright Guestbook | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) url, (2) city, (3) state, or (4) country parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information,… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Chipmunk Scripts Chipmunk Guestbook | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in admin/login.php in Chipmunk Guestbook allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the User name. | |
| Modificada | Baja (2.6) | 1.8% | — | Skullsplitter PHP Guestbook | 19/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guestbook.php in Soren Boysen (SkullSplitter) PHP Guestbook 2.6 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Dvguestbook | 8/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Dvguestbook | 8/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter. | |
| Modificada | Media (6.4) | 2.3% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in signed.php in Hinton Design phphg Guestbook 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) location, (2) website, or (3) message parameter. | |
| Modificada | Alta (7.5) | 2.2% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or the id parameter to (2) admin/edit_smilie.php, (3) admin/add_theme.php, (4) admin/ban_ip.php, (5) admin/add_lang.php, or (6)… | |
| Modificada | Alta (7.5) | 2.7% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows remote attackers to gain unauthorized access. | |
| Modificada | Media (4.3) | 1.2% | — | Tachyon Vanilla Guestbook | 4/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to inject arbitrary web script or HTML via unknown vectors related to "posting new messages." | |
| Modificada | Alta (7.5) | 1.2% | — | Tachyon Vanilla Guestbook | 4/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Tachyon Vanilla Guestbook 1.0 beta allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | — | Nukedweb Guestbookhost | 4/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in config.php in NukedWeb GuestBookHost 2005.04.25 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameters. | |
| Modificada | Media (4.3) | 1.2% | — | Punctweb Myco Guestbook | 1/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyCO Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the Name field, when registering a user. | |
| Modificada | Alta (7.5) | 1.3% | — | Punctweb Myco Guestbook | 1/2/2006 | 16/6/2026 | MyCO Guestbook 1.0 stores the admin directory under the web document root with insufficient access control, which allows remote attackers to perform unspecified privileged actions by directly accessing files via a URL. | |
| Modificada | Media (4.3) | 1.8% | — | MY Little Homepage MY Little Guestbook | 31/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guestbook.php in my little homepage my little guestbook, as last modified in March 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags. | |
| Modificada | Media (4.3) | 1.2% | — | Chipmunk Scripts Chipmunk Guestbook | 3/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ooapp Guestbook | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in home.php in OoApp Guestbook 2.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter. |