Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Revou Micro Blogging Twitter Clone | 25/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Fullrevolution Aspwebalbum | 19/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in pics/, related to the uploadmedia action in album.asp. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Fullrevolution Aspwebalbum | 19/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a summary action. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Revou | 24/4/2009 | 16/6/2026 | adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator's password and gain privileges via a direct request with modified newpass1 and newpass2 parameters in a Change… | |
| Modificada | Media (6.8) | 3.6% | 💥 Exploit | Revou Tclone | 24/4/2009 | 16/6/2026 | Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo. | |
| Modificada | Media (5) | 1.1% | — | Fullrevolution Aspwebcalendar | 2/4/2009 | 16/6/2026 | aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb. | |
| Modificada | Alta (10) | 12% | 💥 Exploit | Fullrevolution Aspwebcalendar2008 | 24/6/2008 | 16/6/2026 | Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Revokesoft Revokebb | 19/6/2008 | 16/6/2026 | SQL injection vulnerability in inc/class_search.php in the Search System in RevokeBB 1.0 RC11 allows remote attackers to execute arbitrary SQL commands via the search parameter. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | ROI Revolution Urchin | 26/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, a different vulnerability than CVE-2007-4713. NOTE: this can be leveraged to capture login credentials in some browsers… | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | ROI Revolution Urchin | 26/9/2007 | 16/6/2026 | report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112. | |
| Modificada | Alta (7.5) | 6.1% | 💥 Exploit | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet. | |
| Modificada | Alta (7.5) | 3.7% | — | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname. | |
| Modificada | Media (4.3) | 1.2% | — | ROI Revolution Urchin | 5/9/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in urchin.cgi in Urchin 5.6.00r2 allow remote attackers to inject arbitrary web script or HTML via the (1) dtc, (2) vid, (3) n, (4) dt, (5) ed, and (6) bd parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Revokesoft Revokebb | 6/6/2007 | 16/6/2026 | SQL injection vulnerability in inc/class_users.php in RevokeSoft RevokeBB 1.0 RC4 and earlier allows remote attackers to execute arbitrary SQL commands via the revokebb_user cookie. | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Post Revolution | 24/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Revolutionproducts Flexbb | 28/3/2007 | 16/6/2026 | SQL injection vulnerability in includes/start.php in Flexbb 1.0.0 10005 Beta Release 1 allows remote attackers to execute arbitrary SQL commands via the flexbb_lang_id COOKIE parameter to index.php. | |
| Modificada | Alta (10) | 3.8% | — | Trevorchan | 9/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in Trevorchan 0.7 and earlier allows remote attackers to execute arbitrary code via the tc_config[rootdir] parameter to (1) upgrade.php, (2) paint_save.php, (3) menu.php, (4) manage.php, and (5) banned.php. NOTE: his issue has been disputed by reliable third parties, who state… | |
| Modificada | Media (5) | 1.8% | 💥 Exploit | Full Revolution Aspweblinks | 6/6/2006 | 16/6/2026 | links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Full Revolution Aspweblinks | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Revoboard | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RevoBoard 1.8, as derived from PunBB, allows remote attackers to inject arbitrary web script or HTML via a substitution cipher of the email tag, which is transformed when the application's e-mail address obfuscator reverses the transformation. NOTE: it is not clear whether… | |
| Modificada | Media (5) | 1.7% | — | Trevor Hogan Bnbt | 6/9/2005 | 16/6/2026 | client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+5 | 2/5/2005 | 16/6/2026 | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has… | |
| Modificada | Media (5) | 1.7% | — | Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+5 | 2/5/2005 | 16/6/2026 | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Fullrevolution Aspwebalbum | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the cat parameter to album.asp. NOTE: it was later reported that vector 1 affects aspWebAlbum 3.2, and the vector involves the txtUserName parameter in a… | |
| Modificada | Alta (7.5) | 4.1% | 💥 Exploit | Full Revolution Aspwebcalendar | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the username field on the login page or (2) the eventid parameter to calendar.asp. |