Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3145▲ 571 respecto a la semana anterior
Críticas / altas1455▲ 53 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

2140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.2%💥 ExploitHinton Design Phpht Topsites23/10/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en common.php en Hinton Design phpht Topsites permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro phpht_real_path.
ModificadaAlta (7.5)1.5%—Comdev Form Designer20/10/200616/6/2026
Vulnerabilidad PHP de inclusion remota de archivo en adminfoot.php en Comdev Form Designer 4.1, cuando register_globals está habilitado, permite a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro path[docroot]. NOTA: el origen de esta información es desconocida; los detalles se…
ModificadaAlta (7.5)1.5%—Dayfox Designs Dayfox Blog10/10/200616/6/2026
Múltiples vulnerabilidades de inclusión remota de archivo en PHP en Dayfox Designs Dayvox Blog 2.0 permiten a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro slogin en los ficheros(1) adminlog.php, (2) postblog.php, (3) index.php, o (4) index2.php en /edit.
ModificadaAlta (7.5)2.5%—Artmedic Webdesign Artmedic Links21/9/200616/6/2026
Vulnerabilidad PHP de inclusión remota de archivo en index.php en Artmedic Links 5.0 permite a atacantes remotos ejecutar código PHP de su elección vía una URL en el parámetro id, el cual es procesado por la función readfile.
ModificadaMedia (5.1)16%💥 ExploitTelekorn Signkorn Guestbook19/9/200616/6/2026
Múltiples vulnerabilidades PHP de inclusión remota de archivo en Telekorn SignKorn Guestbook (SL) 1.3 y anteriores, cuando register_globals está activado, permite a atacantes remotos ejecutar código PHP de su elección vía una URL en el parámetro dir_path en (1) index.php, (2) includes/functions.gb.php, (3)…
ModificadaMedia (4.3)1.2%—CJ Design CJ TAG Board14/9/200616/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en tag.php en CloudNine Interactive CJ Tag Board 3.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante un evento JavaScript en una etiqueta url en BBcode en el parámetro cjmsg.
ModificadaMedia (5.1)7.7%💥 ExploitTelekorn Signkorn Guestbook14/9/200616/6/2026
Vulnerabilidad PHP de inclusión remota de archivo en includes/log.inc.php en Telekorn SignKorn Guestbook (SL) 1.3 y anteriores, cuando register_globals está habilitado y el parámetro _SESSION[permission] está configurado como "yes", permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el…
ModificadaAlta (7.5)1.6%—CJ Design CJ TAG Board30/8/200616/6/2026
Vulnerabilidad de inyección directa de código estático en CJ Tag Board 3.0 permite a atacantes remotos ejecutar código PHP de su elección mediante la (1) cabecera HTTP User-Agent en tag.php, que es ejecutado por all.php, y (2) el parámetro banned en admin_index.php.
ModificadaAlta (7.5)1.6%—Arthur Konze Webdesign Akocomment21/8/200616/6/2026
Vulnerabilidad de inclusión remota de archivo en PHP en akocomments.php en el módulo AkoComment 1.1 (com_akocomment) para Mambo 4.5 permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro mosConfig_absolute_path.
ModificadaMedia (4.3)1.3%—Huttenlocher Webdesign Hwdeguest21/7/200616/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Huttenlocher Webdesign hwdeGUEST 2.1.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección, como se ha demostrado con el campo "name input" (inserción de nombre) en new_entry.php.
ModificadaMedia (5.1)3.1%💥 ExploitWebdesignhq Sitebuilder-fx6/7/200616/6/2026
Vulnerabilidad de inclusión remota de fichero en top.php en SiteBuilder-FX v3.5, permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro admindir.
ModificadaMedia (4.3)1.4%—Virtual Design Studios Vlbook27/6/200616/6/2026
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en index.php en vlbook v1.02, permite a atacantes remotos inyectar secuencias de comandos web de su elección a través del parámetro "message".
ModificadaAlta (7.5)1.3%—TPL Design Tplshop22/6/200616/6/2026
Vulnerabilidad de inyección SQL en category.php en TPL Design tplShop v2.0 y anteriores , permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro first_row.
ModificadaMedia (4.3)1.3%—Pensacola WEB Designs Xtreme ASP Photo Gallery15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp.
ModificadaMedia (6.8)1.7%—Lucid Designs Lucid Calendar15/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaAlta (7.5)2.0%—OUT OF THE Trees WEB Design Selectapix9/6/200616/6/2026
Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php.
ModificadaBaja (2.6)2.1%—OUT OF THE Trees WEB Design Selectapix9/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php.
ModificadaMedia (6.8)4.0%💥 ExploitEpic Designs Tinybb1/6/200616/6/2026
Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) password parameters in (b) login.php, and other unspecified vectors.
ModificadaMedia (6.4)1.8%💥 ExploitEpic Designs Eggblog1/6/200616/6/2026
SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5.1)8.8%💥 ExploitEpic Designs Tinybb1/6/200616/6/2026
PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_footers parameter.
ModificadaAlta (7.5)1.7%—Epic Designs Eggblog1/6/200616/6/2026
home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter.
ModificadaMedia (6.8)1.6%—Epic Designs Tinybb1/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 allow remote attackers to inject arbitrary web script or HTML via the q parameter in forgot.php, which is echoed in an error message, and other unspecified vectors.
ModificadaAlta (7.5)1.1%—OUT OF THE Trees WEB Design Selectapix1/6/200616/6/2026
SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources.
ModificadaMedia (5.1)1.1%—Artmedic Webdesign Artmedic Newsletter26/5/200616/6/2026
artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (5.1)2.6%💥 ExploitArtmedic Webdesign Artmedic Newsletter26/5/200616/6/2026
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as…
Orbitaley — Vulnerabilidades