Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
2140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Dayfox Designs Dayfox Blog | 22/5/2006 | 16/6/2026 | Dayfox Blog 2.0 and earlier stores user credentials in edit/slog_users.txt under the web document root with insufficient access control, which allows remote attackers to gain privileges. | |
| Modificada | Media (5) | 1.3% | — | OUT OF THE Trees WEB Design Selectapix | 19/5/2006 | 16/6/2026 | view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter. | |
| Modificada | Media (6.8) | 8.7% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | E-Business Designer (eBD) 3.1.4 y versiones anteriores permite a atacantes remotos subir o modificar archivos arbitrarios y ejecutar código arbitrario, a través de una petición directa a (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html o (3)… | |
| Modificada | Baja (2.6) | 1.2% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in form_grupo.html in E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection. | |
| Modificada | Media (5) | 1.4% | — | Oasyssoft E-business Designer | 12/5/2006 | 16/6/2026 | E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web server via "'" characters, and possibly other invalid values, in (1) the id parameter to form_grupo.html, or requests to the (2) archivos/ and (3) files/ directories. NOTE: this issue might be resultant from SQL… | |
| Modificada | Alta (9.3) | 3.3% | — | Verisign I-nav | 12/5/2006 | 16/6/2026 | The InstallProduct routine in the Verisign VUpdater.Install (aka i-Nav) ActiveX control does not verify Microsoft Cabinet (.CAB) files, which allows remote attackers to run an arbitrary executable file. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | PHP Design X PHP Linkliste | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Artmedic Webdesign Artmedic Event | 1/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter. | |
| Modificada | Alta (7.6) | 1.8% | 💥 Exploit | Design Nation Dnguestbook | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in Design Nation DNGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) email and (2) id parameters. | |
| Modificada | Media (5.1) | 1.6% | — | Wire Plastik Design Wpblog | 6/4/2006 | 16/6/2026 | SQL injection vulnerability in index.php in wpBlog 0.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter. | |
| Modificada | Media (5.1) | 1.3% | — | R2xdesign Qlitenews | 1/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Vihordesign | 30/3/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Vihordesign | 30/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error… | |
| Modificada | Media (5) | 1.1% | 💥 Exploit | Jjwwebdesign Phpbookingcalendar | 28/3/2006 | 16/6/2026 | SQL injection vulnerability in details_view.php in PHP Booking Calendar 1.0c and earlier allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | |
| Modificada | Media (5.1) | 1.2% | — | Arthur Konze Webdesign Akocomment | 28/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in akocomment.php in AkoComment 2.0 module for Mambo, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) acname or (2) contentid parameter. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Verisign Mpki | 22/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as used in Managed PKI (MPKI) 6.0, allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the VHTML_FILE parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Dci-designs Dawaween | 7/3/2006 | 16/6/2026 | SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a diwan view action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Dci-designs Dci-taskeen | 1/3/2006 | 16/6/2026 | SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Hinton Design Phpht Topsites | 13/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hinton Design phpht Topsites 1.3 allow remote attackers to execute arbitrary SQL commands via multiple vectors including the username parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Hinton Design Phpht Topsites | 13/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) link_edited.php and (2) link_added.php in Hinton Design phpht Topsites 1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.8% | — | Hinton Design Phpht Topsites | 13/2/2006 | 16/6/2026 | check.php in Hinton Design phpht Topsites 1.3 does not validate passwords when using cookies, which allows remote attackers to bypass authentication via unspecified cookies. | |
| Modificada | Alta (7.5) | 2.2% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hinton Design phphg Guestbook 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) username parameter to check.php or the id parameter to (2) admin/edit_smilie.php, (3) admin/add_theme.php, (4) admin/ban_ip.php, (5) admin/add_lang.php, or (6)… | |
| Modificada | Alta (7.5) | 2.7% | — | Hinton Design Phphg Guestbook | 8/2/2006 | 16/6/2026 | check.php in Hinton Design phphg Guestbook 1.2 does not check the user password when authenticating via cookies, which allows remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 1.6% | — | Hinton Design Phphd | 8/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Hinton Design phphd 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to check.php or (2) unknown attack vectors to scripts that display information from the database. | |
| Modificada | Alta (7.5) | 2.0% | — | Hinton Design Phphd | 8/2/2006 | 16/6/2026 | check.php in Hinton Design phphd 1.0 does not check passwords when certain cookies are provided, which allows remote attackers to bypass authentication. |