Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
2145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Turnkey WEB Tools PHP Simple Shop | 10/8/2006 | 16/6/2026 | Múltiples vulnerabilidades PHP de inclusión remota de archivo en Turnkey Web Tools PHP Simple Shop 2.0 y anteriores permiten a un atacante remoto ejecutar código PHP de su elección a través de una URL en el parámetro abs_path a (1) admin/index.php, (2) admin/adminindex.php, (3) admin/adminglobal.php, (4)… | |
| Modificada | Media (6.8) | 3.6% | 💥 Exploit | Mamboxchange Simpleboard | 12/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de inclusión de archivo PHP remoto en el módulo Simpleboard de Mambo 1.1.0 y anteriores permite a atacantes remotos ejecutar código PHP de su elección a través de un URL en el parámetro sbp a (1) image_upload.php y (2) file_upload.php. | |
| Modificada | Baja (2.6) | 1.3% | — | Onedotoh Simple File Manager | 22/6/2006 | 16/6/2026 | vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en fm.php en ONEdotOH Simple File Manager (SFM) v0.24a y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro MSG. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Baby Katie Media Very Simple CAR ListerBaby Katie Media Very Simple Realty Lister | 13/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsREAL) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) lid parameter in index.php and the (2) title parameter in myslideshow.php. | |
| Modificada | Media (6.8) | 1.5% | — | TWO Shoes Mambo Factory Simpleboard | 5/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Two Shoes M-Factory (TSMF) SimpleBoard 1.1.0 Stable (aka com_simpleboard), as used in Mambo and Joomla!, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in "post ne topic" in the Frontend, (2) the Title (aka Community-Title)… | |
| Modificada | Media (4.3) | 1.3% | — | Phpsimplechoose | 30/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the input forms in prattmic and Master5006 PHPSimpleChoose 0.3 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. | |
| Modificada | Alta (7.6) | 2.5% | — | Codemunkyx Simple Poll | 5/5/2006 | 16/6/2026 | CodeMunkyX (aka free-php.net) Simple Poll 1.0, when authentication is not required for the admin directory, allows remote attackers to gain administrative privileges by appending /admin/ to the top-level URI of the application. | |
| Modificada | Alta (7.5) | 3.3% | — | SWS Simple WEB Server | 1/5/2006 | 16/6/2026 | Format string vulnerability in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via unspecified vectors that are not properly handled in a syslog function call. | |
| Modificada | Alta (7.5) | 3.7% | — | SWS Simple WEB Server | 1/5/2006 | 16/6/2026 | Buffer overflow in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via a long request. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Simplemedia Simplebbs | 18/4/2006 | 16/6/2026 | Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log. | |
| Modificada | Alta (10) | 3.6% | — | Himpfen Consulting PHP Simplenews | 19/3/2006 | 16/6/2026 | admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie. | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 15/3/2006 | 16/6/2026 | Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache… | |
| Modificada | Media (4.3) | 1.8% | — | Simple Machines Forum | 25/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sources/Register.php in Simple Machine Forum (SMF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For HTTP header field. | |
| Modificada | Media (5.8) | 1.5% | — | 8pixel.net Simple Blog | 18/1/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Simple Blog 2.1 allow remote attackers to inject arbitrary web script or HTML via (1) a comment to comments.asp and (2) possibly certain other fields in unspecified scripts. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | 8pixel.net Simple Blog | 18/1/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts. | |
| Modificada | Media (4.3) | 1.3% | — | Enhanced Simple PHP Gallery | 7/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | |
| Modificada | Media (5) | 1.5% | — | Enhanced Simple PHP Gallery | 7/1/2006 | 16/6/2026 | Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message. | |
| Modificada | Media (4.3) | 1.3% | — | Citypost Simple Image Editor | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in image-editor-52/index.php in CityPost Simple Image-Editor 0.52 allows remote attackers to inject arbitrary web script or HTML via the (1) m1, (2) m2, (3) m3, (4) imgsrc, and (5) m4 parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Citypost Simple PHP Upload | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Simple Machines Forum | 11/12/2005 | 16/6/2026 | ** DISPUTADA ** El fabricante y terceras partes han disputado este asunto. Vulnerabilidad de inyección de SQL en Memberlist.php en Simple Machines Forum (SMF) 1.1 rc1 y anteriores permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro "start". NOTA: El fabricante afirma que, dado que… | |
| Modificada | Alta (7.5) | 8.6% | 💥 Exploit | Simplemedia Simplebbs | 9/12/2005 | 16/6/2026 | Direct static code injection vulnerability in includes/newtopic.php in SimpleBBS 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the Host header (possibly the name parameter or variable), which is then written to data/topics.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Simplemedia Simplebbs | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in SimpleBBS 1.1 allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Cafuego Simple Document Management System | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Simple Document Management System (SDMS) 2.0-CVS and earlier allow remote attackers to execute arbitrary SQL commands via the (1) folder_id parameter in list.php and (2) mid parameter in a view action to messages.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Simplepoll | 22/11/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en results.php de SimplePolls permite a atacantes remotos ejecutar comandos SQL de su elección mediante el parámetro "pollid". | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Alexander Palmo Simple PHP Blog | 3/11/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) in (a) preview_cgi.php and (b) preview_static_cgi.php, or (4)… |