Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3145▲ 571 respecto a la semana anterior
Críticas / altas1455▲ 53 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
2140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Hinton Design Phpht Topsites | 23/10/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en common.php en Hinton Design phpht Topsites permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro phpht_real_path. | |
| Modificada | Alta (7.5) | 1.5% | — | Comdev Form Designer | 20/10/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusion remota de archivo en adminfoot.php en Comdev Form Designer 4.1, cuando register_globals está habilitado, permite a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro path[docroot]. NOTA: el origen de esta información es desconocida; los detalles se… | |
| Modificada | Alta (7.5) | 1.5% | — | Dayfox Designs Dayfox Blog | 10/10/2006 | 16/6/2026 | Múltiples vulnerabilidades de inclusión remota de archivo en PHP en Dayfox Designs Dayvox Blog 2.0 permiten a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro slogin en los ficheros(1) adminlog.php, (2) postblog.php, (3) index.php, o (4) index2.php en /edit. | |
| Modificada | Alta (7.5) | 2.5% | — | Artmedic Webdesign Artmedic Links | 21/9/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en index.php en Artmedic Links 5.0 permite a atacantes remotos ejecutar código PHP de su elección vía una URL en el parámetro id, el cual es procesado por la función readfile. | |
| Modificada | Media (5.1) | 16% | 💥 Exploit | Telekorn Signkorn Guestbook | 19/9/2006 | 16/6/2026 | Múltiples vulnerabilidades PHP de inclusión remota de archivo en Telekorn SignKorn Guestbook (SL) 1.3 y anteriores, cuando register_globals está activado, permite a atacantes remotos ejecutar código PHP de su elección vía una URL en el parámetro dir_path en (1) index.php, (2) includes/functions.gb.php, (3)… | |
| Modificada | Media (4.3) | 1.2% | — | CJ Design CJ TAG Board | 14/9/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en tag.php en CloudNine Interactive CJ Tag Board 3.0 permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante un evento JavaScript en una etiqueta url en BBcode en el parámetro cjmsg. | |
| Modificada | Media (5.1) | 7.7% | 💥 Exploit | Telekorn Signkorn Guestbook | 14/9/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en includes/log.inc.php en Telekorn SignKorn Guestbook (SL) 1.3 y anteriores, cuando register_globals está habilitado y el parámetro _SESSION[permission] está configurado como "yes", permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el… | |
| Modificada | Alta (7.5) | 1.6% | — | CJ Design CJ TAG Board | 30/8/2006 | 16/6/2026 | Vulnerabilidad de inyección directa de código estático en CJ Tag Board 3.0 permite a atacantes remotos ejecutar código PHP de su elección mediante la (1) cabecera HTTP User-Agent en tag.php, que es ejecutado por all.php, y (2) el parámetro banned en admin_index.php. | |
| Modificada | Alta (7.5) | 1.6% | — | Arthur Konze Webdesign Akocomment | 21/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en akocomments.php en el módulo AkoComment 1.1 (com_akocomment) para Mambo 4.5 permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro mosConfig_absolute_path. | |
| Modificada | Media (4.3) | 1.3% | — | Huttenlocher Webdesign Hwdeguest | 21/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Huttenlocher Webdesign hwdeGUEST 2.1.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección, como se ha demostrado con el campo "name input" (inserción de nombre) en new_entry.php. | |
| Modificada | Media (5.1) | 3.1% | 💥 Exploit | Webdesignhq Sitebuilder-fx | 6/7/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de fichero en top.php en SiteBuilder-FX v3.5, permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro admindir. | |
| Modificada | Media (4.3) | 1.4% | — | Virtual Design Studios Vlbook | 27/6/2006 | 16/6/2026 | Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en index.php en vlbook v1.02, permite a atacantes remotos inyectar secuencias de comandos web de su elección a través del parámetro "message". | |
| Modificada | Alta (7.5) | 1.3% | — | TPL Design Tplshop | 22/6/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en category.php en TPL Design tplShop v2.0 y anteriores , permite a atacantes remotos ejecutar comandos SQL de su elección a través del parámetro first_row. | |
| Modificada | Media (4.3) | 1.3% | — | Pensacola WEB Designs Xtreme ASP Photo Gallery | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp. | |
| Modificada | Media (6.8) | 1.7% | — | Lucid Designs Lucid Calendar | 15/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.0% | — | OUT OF THE Trees WEB Design Selectapix | 9/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php. | |
| Modificada | Baja (2.6) | 2.1% | — | OUT OF THE Trees WEB Design Selectapix | 9/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php. | |
| Modificada | Media (6.8) | 4.0% | 💥 Exploit | Epic Designs Tinybb | 1/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) password parameters in (b) login.php, and other unspecified vectors. | |
| Modificada | Media (6.4) | 1.8% | 💥 Exploit | Epic Designs Eggblog | 1/6/2006 | 16/6/2026 | SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5.1) | 8.8% | 💥 Exploit | Epic Designs Tinybb | 1/6/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_footers parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Epic Designs Eggblog | 1/6/2006 | 16/6/2026 | home/register.php in Eggblog before 3.0 allows remote attackers to change the password of administrators and possibly other users via a modified username parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Epic Designs Tinybb | 1/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Epicdesigns tinyBB 0.3 allow remote attackers to inject arbitrary web script or HTML via the q parameter in forgot.php, which is echoed in an error message, and other unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | OUT OF THE Trees WEB Design Selectapix | 1/6/2006 | 16/6/2026 | SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources. | |
| Modificada | Media (5.1) | 1.1% | — | Artmedic Webdesign Artmedic Newsletter | 26/5/2006 | 16/6/2026 | artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (5.1) | 2.6% | 💥 Exploit | Artmedic Webdesign Artmedic Newsletter | 26/5/2006 | 16/6/2026 | artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as… |