Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | AJ Square AJ Auction | 24/11/2008 | 16/6/2026 | SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | AJ Square INC RSS Reader | 27/10/2008 | 16/6/2026 | SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL commands via the url parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | AJ Square AJ Hyip | 11/9/2008 | 16/6/2026 | SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the artid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | AJ Square AJ Hyip | 11/9/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL commands via the artid parameter to (1) acme/article/comment.php and (2) prime/article/comment.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Ajhyip AJ Square Aj-hyip | 27/6/2008 | 16/6/2026 | SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | AJ Square AJ Auction | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | AJ Square AJ Hyip | 3/6/2008 | 16/6/2026 | SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Sejoong Namo ActivesquareSejoong Namo Namoinstall.1 Activex Control | 6/2/2008 | 16/6/2026 | Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551. | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | Microsoft ActivexSejoong Namo Activesquare | 1/2/2008 | 16/6/2026 | The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | AJ Square Ajauction | 7/3/2007 | 16/6/2026 | SQL injection vulnerability in subcat.php in AJ Auction 1.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | AJ Square AJ Classifieds | 7/3/2007 | 16/6/2026 | SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | AJ Square Ajdating | 7/3/2007 | 16/6/2026 | SQL injection vulnerability in view_profile.php in AJDating 1.0 allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | |
| Modificada | Media (5) | 1.8% | — | Threesquared.net PHP Download Script | 9/9/2006 | 16/6/2026 | Directory traversal vulnerability in download/index.php, and possibly download.php, in threesquared.net (aka Ben Speakman) Php download allows remote attackers to overwrite arbitrary local files via .. (dot dot) sequence in the file parameter. | |
| Modificada | Media (5) | 4.5% | 💥 Exploit | Net-square Httprint | 22/12/2005 | 16/6/2026 | httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTTP response. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Net-square Httprint | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response, which is not sanitized before being displayed to the user. | |
| Modificada | Media (4.3) | 1.2% | — | Quicksquare Development Honeycomb Archive Enterprise | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Quicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise | 20/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters. |