Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

224 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.7%💥 ExploitAdes Design Adesguestbook31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in read.php in AdesGuestbook 2.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_rsRead parameter.
ModificadaMedia (4.3)1.2%—Advanced Guestbook31/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php/entry vector might be resultant from CVE-2005-1548.
ModificadaMedia (4.3)1.2%—Epistream Ipei Guestbook31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 1.7 allows remote attackers to inject arbitrary web script or HTML via the email parameter, as used by the email field, when signing a guestbook.
ModificadaAlta (7.5)1.2%—Advanced Guestbook16/11/200516/6/2026
SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field.
ModificadaMedia (5)1.4%—Chipmunk Scripts Chipmunk Guestbook6/11/200516/6/2026
Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.
ModificadaMedia (4.3)1.2%—Emefa Guestbook23/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.
ModificadaMedia (5)2.3%💥 ExploitLevcgi.com Myguestbook6/7/200516/6/2026
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
ModificadaMedia (4.3)0.95%—Episodex Guestbook20/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in default.asp for episodex guestbook allows remote attackers to inject arbitrary web script or HTML via the Name field and other fields.
ModificadaAlta (7.5)1.7%—Episodex Guestbook20/5/200516/6/2026
episodex guestbook allows remote attackers to bypass authentication and edit scripts via a direct request to admin.asp.
ModificadaAlta (7.5)1.7%—Htmljunction Ezguestbook18/5/200516/6/2026
HTMLJunction EZGuestbook stores the guestbook.mdb file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the administrative password.
ModificadaMedia (4.3)2.7%💥 ExploitSoren Boysen Skull-splitter Guestbook16/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Skull-Splitter Guestbook 1.0, 2.0 and 2.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
ModificadaAlta (7.5)1.1%💥 ExploitAdvanced Guestbook14/5/200516/6/2026
SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
ModificadaMedia (4.3)1.4%—Pixysoft Guestbook PRO11/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
ModificadaMedia (5)1.5%—Uapplication Uguestbook3/5/200516/6/2026
Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.
ModificadaAlta (7.5)1.2%—Abczone.it Wwwguestbook3/5/200516/6/2026
SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.
ModificadaAlta (7.5)1.0%💥 ExploitEcomm Professional Guestbook3/5/200516/6/2026
SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.
ModificadaAlta (7.5)1.5%—Webmasters-debutants WD Guestbook2/5/200516/6/2026
Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.
ModificadaMedia (5)1.2%—Aspjar Guestbook27/4/200516/6/2026
SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.
ModificadaMedia (5)1.4%—Aspjar Guestbook27/4/200516/6/2026
Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.
ModificadaMedia (4.3)0.96%—HPM Guestbook.cgi30/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.
ModificadaMedia (6.8)2.0%💥 ExploitAdvanced Guestbook10/1/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Advanced Guestbook 2.3.1, 2.2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the entry parameter.
ModificadaAlta (7.5)7.3%💥 ExploitAlexphpteam Alex Guestbook31/12/200416/6/2026
PHP remote file inclusion vulnerability in livre_include.php in @lex Guestbook allows remote attackers to execute arbitrary PHP code by modifying the chem_absolu parameter to reference a URL on a remote web server that contains the code.
ModificadaMedia (5)1.5%—Abczone.it Wwwguestbook31/12/200416/6/2026
Abczone.it WWWguestbook 1.1 stores db/dbase.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the plaintext username and password.
ModificadaMedia (6.8)1.5%—Francisco Burzi Php-nukeWarpspeed 4nguestbook31/12/200416/6/2026
SQL injection vulnerability in 4nGuestbook 0.92 for PHP-Nuke 6.5 through 6.9 allows remote attackers to modify SQL statements via the entry parameter to modules.php, which can also facilitate cross-site scripting (XSS) attacks when MySQL errors are triggered.
ModificadaAlta (7.5)1.2%💥 ExploitAdvanced Guestbook23/4/200416/6/2026
SQL injection vulnerability in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password.
Orbitaley — Vulnerabilidades