Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 247 respecto a la semana anterior
Críticas / altas1338▼ 91 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)1.3%—R2xdesign Qlitenews1/4/200616/6/2026
Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
ModificadaMedia (4.3)1.2%—PHP Lite Calendar Express28/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Calendar Express 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) allwords or (2) oneword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (4.3)1.2%—PHP Lite Meeting Reserve28/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in searchresult.php in Meeting Reserve 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the search_term parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (5.1)1.6%—Jason Smith Cyboards PHP Lite10/3/200616/6/2026
SQL injection vulnerability in CyBoards PHP Lite 1.25, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the parent parameter to (1) post.php and possibly (2) process_post.php.
ModificadaMedia (5.1)1.2%—Mirabilis ICQMirabilis ICQ Lite18/2/200616/6/2026
ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions and bypass Windows security warnings via a filename that ends in an assumed-safe extension such as JPG, and possibly containing other modified…
ModificadaMedia (5.1)1.2%—Mirabilis ICQMirabilis ICQ Lite18/2/200616/6/2026
GUI display truncation vulnerability in ICQ Inc. (formerly Mirabilis) ICQ 2003a, 2003b, Lite 4.0, Lite 4.1, and possibly other Windows versions allows user-assisted remote attackers to hide malicious file extensions, bypass Windows security warnings via a filename that is all uppercase and of a specific length, which…
ModificadaBaja (2.6)1.6%—Reamday Enterprises Magic News Lite16/2/200616/6/2026
preview.php en Reamday Enterprises Magic News Lite 1.2.3, cuando "register_globals" está habilitado, permite a atacantes remotos incluir ficheros arbitrarios mediante una URL en el parámetro php_script_path, que no es inicializado.
ModificadaBaja (2.6)1.3%—Reamday Enterprises Magic News Lite16/2/200616/6/2026
profile.php en Reamday Enterprises Magic News Lite 1.2.3, cuando "register_globals" está habilitado, permite a atacantes remotos modificar el comportamiento del programa, potencialmente evitando controles de autenticación, mediante la modificación de las variables (1) action, (2) passwd, (3) admin_password, (4)…
ModificadaAlta (7.5)2.1%💥 ExploitReamday Enterprises Magic Calendar Lite13/2/200616/6/2026
Multiple SQL injection vulnerabilities in cms/index.php in Magic Calendar Lite 1.02, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) $total_login and (2) $total_password parameter.
ModificadaAlta (7.5)1.3%—PHP Lite Calendar Express5/12/200516/6/2026
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (b) week.php, (c) month.php, and (d) year.php.
ModificadaAlta (7.5)1.3%💥 ExploitPhpyellowtm LitePhpyellowtm PRO5/12/200516/6/2026
Multiple SQL injection vulnerabilities in phpYellowTM Pro Edition and Lite Edition 5.33 allow remote attackers to execute arbitrary SQL commands via the (1) haystack parameter to search_result.php or (2) ckey parameter to print_me.php.
ModificadaAlta (7.5)1.2%—Td-systems Adc2000 NG PROTd-systems Adc2000 NG PRO Lite29/11/200516/6/2026
Multiple SQL injection vulnerabilities in adcbrowres.php in AD Center ADC2000 NG Pro 1.2 and NG Pro Lite allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) lang parameters.
ModificadaMedia (4.3)1.2%—Onlinetechtools.com Okbsys Lite27/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in Online Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the q parameter.
ModificadaMedia (4.3)1.2%—Onlinetechtools.com Oasys Lite27/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.
ModificadaAlta (7.5)1.2%—Onlinetechtools.com Owos Lite27/11/200516/6/2026
SQL injection vulnerability in search.asp in Online Work Order Suite (OWOS) Lite Edition for ASP 3.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
ModificadaMedia (4.3)1.9%💥 ExploitLitespeed Technologies Litespeed WEB Server20/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
ModificadaAlta (7.5)4.7%—Oracle Database ServerOracle Database Server LiteOracle10gOracle8i+116/11/200516/6/2026
Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.
ModificadaMedia (4.3)2.2%💥 ExploitElite Forum1/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a topic, in which the reply contains a javascript: URL in an <img> tag.
ModificadaMedia (4.3)1.4%💥 ExploitComersus Open Technologies Comersus Backoffice LiteComersus Open Technologies Comersus Backoffice Plus1/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by CVE-2005-2191 item 2.
ModificadaAlta (7.5)1.7%—Perception Liteweb9/6/200516/6/2026
Perception LiteWeb allows remote attackers to bypass access controls for files via an extra leading / (slash) or leading \ (backslash) in the URL.
ModificadaAlta (7.5)2.4%💥 ExploitQualiteam X-cart1/6/200516/6/2026
Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to help.php, (7) mode…
ModificadaMedia (4.3)3.6%💥 ExploitQualiteam X-cart1/6/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error_message.php, (6) section parameter to…
ModificadaMedia (4.3)0.94%—Freestyle WikiFreestyle Wikilite31/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
ModificadaBaja (2.1)0.32%—Willings WebcamWillings Webcam Lite16/5/200516/6/2026
Willings WebCam and WebCam Lite 2.8 and earlier stores the password in memory in plaintext, which allows local users to gain sensitive information.
ModificadaMedia (5)1.3%—Spidean At-liteSpidean Autotheme16/5/200516/6/2026
Multiple unknown vulnerabilities in the Blocks module in Spidean AutoTheme 1.7 and AT-Lite for PostNuke have unknown impact.