Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.97%💥 ExploitAJ Square AJ Auction24/11/200816/6/2026
SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitAJ Square INC RSS Reader27/10/200816/6/2026
SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter.
ModificadaAlta (7.5)1.00%💥 ExploitAJ Square AJ Hyip11/9/200816/6/2026
SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the artid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitAJ Square AJ Hyip11/9/200816/6/2026
Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL commands via the artid parameter to (1) acme/article/comment.php and (2) prime/article/comment.php.
ModificadaAlta (7.5)0.97%💥 ExploitAjhyip AJ Square Aj-hyip27/6/200816/6/2026
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532.
ModificadaAlta (7.5)0.97%💥 ExploitAJ Square AJ Auction25/6/200816/6/2026
SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitAJ Square AJ Hyip3/6/200816/6/2026
SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)4.6%💥 ExploitSejoong Namo ActivesquareSejoong Namo Namoinstall.1 Activex Control6/2/200816/6/2026
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.
ModificadaAlta (9.3)30%💥 ExploitMicrosoft ActivexSejoong Namo Activesquare1/2/200816/6/2026
The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitAJ Square Ajauction7/3/200716/6/2026
SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
ModificadaAlta (7.5)1.1%💥 ExploitAJ Square AJ Classifieds7/3/200716/6/2026
SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter.
ModificadaAlta (7.5)2.0%💥 ExploitAJ Square Ajdating7/3/200716/6/2026
SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter.
ModificadaMedia (5)1.8%—Threesquared.net PHP Download Script9/9/200616/6/2026
Directory traversal vulnerability in download/index.php, and possibly download.php, in threesquared.net (aka Ben Speakman) Php download allows remote attackers to overwrite arbitrary local files via .. (dot dot) sequence in the file parameter.
ModificadaMedia (5)4.5%💥 ExploitNet-square Httprint22/12/200516/6/2026
httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTTP response.
ModificadaMedia (4.3)2.5%💥 ExploitNet-square Httprint22/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response, which is not sanitized before being displayed to the user.
ModificadaMedia (4.3)1.2%—Quicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm.
ModificadaAlta (7.5)1.2%💥 ExploitQuicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise20/12/200516/6/2026
Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters.
Orbitaley — Vulnerabilidades