Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

236 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.94%—FlatcalendarxpPopcalendarxp18/5/201717/6/2026
Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in iflateng.htm and nflateng.htm. CalendarXP PopCalendarXP through 9.8.308 has XSS in ipopeng.htm and npopeng.htm.
ModificadaAlta (7.5)1.9%—Flatcore-cms10/5/201717/6/2026
acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF.
ModificadaAlta (7.5)1.0%—Flatcore-cms14/4/201717/6/2026
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.
ModificadaCrítica (9.8)1.0%—Flatcore-cms14/4/201717/6/2026
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database.
ModificadaAlta (8.8)0.91%—Flatcore-cms14/4/201717/6/2026
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.
ModificadaMedia (4.3)1.9%—Flatpress13/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in FlatPress 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the content parameter to the default URI.
ModificadaAlta (7.5)1.3%—Flat Manager Project Flat Manager11/9/201417/6/2026
SQL injection vulnerability in the Flat Manager (flatmgr) extension before 2.7.10 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.2)0.39%—Justsystems AtokJustsystems Atok Flat-rate ServiceJustsystems Just Smile18/1/201316/6/2026
Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the screen lock and execute commands with system privileges via unknown vectors related to "launching external applications."
ModificadaMedia (4.3)1.8%—Basic Webmail Project Basic WebmailJason Flatt Basic Webmail3/12/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.
ModificadaMedia (6.8)3.5%💥 ExploitBugbear Flatout15/9/201216/6/2026
Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field in a bed file.
ModificadaMedia (4.3)1.1%—Flatnux10/9/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2012-03.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title_en, (2) summary_en, or (3) body_en parameter in a submitnews action to the news module, a different vulnerability than CVE-2012-4890. NOTE: the…
ModificadaMedia (4.3)1.4%—Flatnux10/9/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2011 08.09.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) comment to the news, (2) title to the news, or (3) the folder names in a gallery.
ModificadaMedia (5)8.8%💥 ExploitFlatnux6/9/201216/6/2026
Absolute path traversal vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 allows remote administrators to read arbitrary files via a full pathname in the dir parameter in a contents/Files action.
ModificadaMedia (6.8)1.2%💥 ExploitFlatnux6/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in controlcenter.php in FlatnuX CMS 2011 08.09.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts.
ModificadaAlta (7.5)1.1%—Joachim Ruhs Flat Manager23/4/201016/6/2026
SQL injection vulnerability in the Flat Manager (flatmgr) extension before 1.9.16 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)1.5%💥 ExploitFlatpress30/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) contact.php, (2) login.php, and (3) search.php.
ModificadaAlta (7.5)2.3%💥 ExploitNinjadesigns Flatchat29/4/200916/6/2026
Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the with parameter.
ModificadaMedia (6.4)2.2%💥 ExploitCirculargenius Flat Calendar21/4/200916/6/2026
Flat Calendar 1.1 does not properly restrict access to administrative functions, which allows remote attackers to (1) add new events via calAdd.php, as reachable from admin/add.php, or (2) delete events via admin/deleteEvent.php. NOTE: this is only a vulnerability when the administrator does not follow recommendations…
ModificadaAlta (10)8.2%💥 ExploitPicoflat CMS4/4/200916/6/2026
Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagina parameter, a different vulnerability than CVE-2007-5390.
ModificadaMedia (5.1)6.3%💥 ExploitFlatnux13/2/200916/6/2026
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04, when register_globals is enabled and magic_quotes_gpc disabled, allows remote attackers to execute arbitrary PHP code via a URL in the _FNROOTPATH parameter to (1) index.php and (2) filemanager.php.
ModificadaMedia (4.3)1.7%💥 ExploitFlatnux30/12/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter to the default URI; (2) the foto parameter to photo.php in the 05_Foto module; or (3) the name parameter in an insertrecord action to…
ModificadaMedia (4.3)1.2%💥 ExploitFlatnux30/12/200816/6/2026
Cross-site scripting (XSS) vulnerability in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allows remote attackers to inject arbitrary web script or HTML via the name parameter in an updaterecord action to index.php in the 08_Files module. NOTE: the provenance of this information is unknown; the details are obtained solely…
ModificadaMedia (4.3)1.8%💥 ExploitFlatpress29/9/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) pass parameter to login.php, or the (3) name parameter to contact.php.
ModificadaMedia (5)2.8%💥 ExploitFlat PHP Board17/12/200716/6/2026
Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1) create arbitrary files via a .. (dot dot) in the username parameter when registering a user account, and (2) read arbitrary PHP files via a .. (dot dot) in (a) the topic parameter in a topic action…
ModificadaMedia (5)2.4%💥 ExploitFlat PHP Board17/12/200716/6/2026
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_username cookie.
Orbitaley — Vulnerabilidades