Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Creative Software Community Portal | 9/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4)… | |
| Modificada | Media (6.4) | 1.2% | — | Web4future News Portal | 9/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Collaborative Portal Server Project Collaborative Portal Server | 2/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mkportal | 27/4/2006 | 16/6/2026 | SQL injection vulnerability in vb_board_functions.php in MKPortal 1.1, as used with vBulletin 3.5.4 and earlier, allows remote attackers to execute arbitrary SQL commands via the userid parameter. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | Mkportal | 27/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters. | |
| Modificada | Baja (2.6) | 1.3% | — | Kcscripts Portal Pack | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Kcscripts Portal Pack | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. | |
| Modificada | Baja (2.6) | 1.4% | — | Kcscripts CalendarKcscripts Portal Pack | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter. | |
| Modificada | Media (5.8) | 2.0% | — | Kcscripts News PublisherKcscripts Portal Pack | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter. | |
| Modificada | Baja (2.6) | 2.0% | 💥 Exploit | Shadowed Portal | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Pages module in Shadowed Portal allows remote attackers to inject arbitrary web script or HTML via the page parameter to load.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Arab Portal | 7/4/2006 | 16/6/2026 | SQL injection vulnerability in forum.php in Arab Portal 2.0.1 stable allows remote attackers to execute arbitrary SQL commands via the mineID parameter. | |
| Modificada | Baja (2.6) | 1.2% | — | Arab Portal | 7/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0.1 stable allow remote attackers to inject arbitrary web script or HTML via the (1) adminJump and (2) forum_middle parameters in (a) forum.php, and the (3) form parameter in (b) members.php, (c) pm.php, and (d) mail.php. | |
| Modificada | Media (5.1) | 6.6% | 💥 Exploit | Arab Portal | 30/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php. | |
| Modificada | Media (5) | 2.2% | — | Oracle Weblogic Portal | 22/3/2006 | 16/6/2026 | Unspecified vulnerability in BEA WebLogic Portal 8.1 up to SP5 causes a JSR-168 Portlet to be retrieved from the cache for the wrong session, which might allow one user to see a Portlet of another user. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Aspportal | 22/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the downloadid parameter in download_click.asp and (2) content_ID parameter in news/News_Item.asp; authenticated administrators can also conduct attacks via (3) user_id parameter to… | |
| Modificada | Media (4.3) | 1.8% | — | Milkeyway Captive Portal | 19/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) ipAddress, (2) act, (3) username, and (4) unspecified other parameters in (a) authuser.php; and the (5) username and (6) unspecified other parameters… | |
| Modificada | Alta (7.5) | 2.2% | — | Milkeyway Captive Portal | 19/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Milkeyway Captive Portal 0.1 and 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) password, (3) team, (4) level, (5) status, (6) teamname, and (7) teamlead parameters in (a) auth.php; the (8) username, (9) action, and (10) filter… | |
| Modificada | Alta (7.5) | 1.6% | — | Aspportal | 19/3/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en ASPPortal 3.00 tienen vectores de impacto y ataque desconocidos. | |
| Modificada | Media (4.3) | 1.4% | — | Aspportal | 19/3/2006 | 16/6/2026 | Múltiples vulnerabilidades de XSS en ASPPortal 3.00 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores de ataque desconocidos. | |
| Modificada | Alta (7.5) | 1.9% | — | Dsportal Dsnewsletter | 15/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php. | |
| Modificada | Media (5.1) | 2.0% | 💥 Exploit | Dsportal Dslogin | 15/3/2006 | 16/6/2026 | SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php. | |
| Modificada | Media (5.1) | 5.2% | 💥 Exploit | Dsportal Dscounter | 14/3/2006 | 16/6/2026 | SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header. | |
| Modificada | Alta (7.5) | 5.9% | 💥 Exploit | Dsportal Dsdownload | 14/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) search.php and (b) downloads.php. | |
| Modificada | Alta (7.5) | 1.9% | — | Dsportal Dspoll | 14/3/2006 | 16/6/2026 | SQL injection vulnerability in DSPoll 1.1 allows remote attackers to execute arbitrary SQL commands via the pollid parameter to (1) results.php, (2) topolls.php, (3) pollit.php. | |
| Modificada | Baja (2.6) | 3.0% | 💥 Exploit | Codeworx Technologies Dcp-portal | 9/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in the send_write page of (a) index.php; (3) subject, and (4)… |