Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
157 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.3% | — | Geminilabs Site Reviews | 26/6/2018 | 17/6/2026 | Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Hotel Restaurant Reviews AND Feedback Script Project Hotel Restaurant Reviews AND Feedback Script | 13/12/2017 | 17/6/2026 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Booksellerscanada Free Canadian Author Previews | 21/10/2014 | 17/6/2026 | The Free Canadian Author Previews (aka com.booksellerscanada.authorpreview) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 5.3% | 💥 Exploit | Terillion Reviews Plugin | 22/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Zeescripts Zeereviews | 13/8/2008 | 16/6/2026 | SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | |
| Modificada | Media (6.4) | 2.3% | 💥 Exploit | Prozilla Reviews | 15/4/2008 | 16/6/2026 | Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Lykoszine Lykos Reviews Module | 2/4/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attackers to execute arbitrary SQL commands via the uid parameter in a u action. |