Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
254 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Geodesicsolutions Geoclassifieds Enterprise | 2/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in GeoClassifieds Enterprise 2.0.5.2 and earlier allows remote attackers to inject arbitrary web script and HTML via the (1) b[username] and (2) c parameters to (a) index.php, the b[username] parameter to (b) admin/index.php, and (3) c[phone] parameter to register.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | GA Soft Rapid Classified | 13/1/2007 | 16/6/2026 | SQL injection vulnerability in viewad.asp in Rapid Classified 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | GA Soft Rapid Classified | 13/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Rapid Classified 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) reply.asp or (b) view_print.asp, the (2) SH1 parameter to (c) search.asp, the (3) name parameter to reply.asp, or the (4) dosearch parameter to (d)… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Locazolist Classifieds | 9/1/2007 | 16/6/2026 | SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter. | |
| Modificada | Baja (3.5) | 1.8% | 💥 Exploit | Enthrallweb Eclassifieds | 29/12/2006 | 16/6/2026 | myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | PWP Technologies THE Classified AD System | 27/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in PWP Technologies The Classified Ad System allow remote attackers to inject arbitrary web script or HTML via the (1) cat or (2) main parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | PWP Technologies THE Classified AD System | 7/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute arbitrary SQL commands via (1) the main parameter in a view action (includes/mainpage/view.asp) in default.asp or (2) a query in the search engine. | |
| Modificada | Alta (7.5) | 1.7% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 7/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in detail.asp in DuWare DuNews allow remote attackers to execute arbitrary SQL commands via the (1) iNews, (2) iType, or (3) Action parameter. NOTE: the iType parameter in type.asp is covered by CVE-2005-3976. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Enthrallweb Eclassifieds | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Enthrallweb eClassifieds allow remote attackers to execute arbitrary SQL commands via the (1) AD_ID, (2) cat_id, (3) sub_id, and (4) ad_id parameters to (a) ad.asp, the (5) cid parameter to (b) dircat.asp, and the (6) sid parameter to (c) dirSub.asp. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Vspin.net Classified System | 28/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to (a) cat.asp, or the (2) keyword, (3) order, (4) sort, (5) menuSelect, or (6) state parameter to (b) search.asp. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Vspin.net Classified System | 28/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in vSpin.net Classified System 2004 allow remote attackers to inject arbitrary web script or HTML via (1) catname parameter to cat.asp or the (2) minprice parameter to search.asp. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Deltascripts PHP Classifieds | 10/11/2006 | 16/6/2026 | SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Deltascripts PHP Classifieds | 26/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in functions.php in DeltaScripts PHP Classifieds 7.1 allows remote attackers to execute arbitrary PHP code via a URL in the set_path parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Phpoutsourcing Noahs Classifieds | 16/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PhpOutsourcing Noah's Classifieds 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the frommethod parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Deltascripts PHP Classifieds | 10/10/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Joomla Classifieds ComponentJoomla COM Classifieds | 27/9/2006 | 16/6/2026 | Unspecified vulnerability in Classifieds (com_classifieds) component 1.3 and earlier for Joomla! has unspecified impact and attack vectors. | |
| Modificada | Media (5.1) | 1.9% | 💥 Exploit | Geodesicsolutions Geoauctions PremierGeodesicsolutions Geoclassifieds Basic | 25/7/2006 | 16/6/2026 | SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Php-nuke Advanced Classified Module | 18/7/2006 | 16/6/2026 | SQL injection vulnerability in the Nuke Advanced Classifieds module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_ads parameter in an EditAds op. | |
| Modificada | Alta (7.5) | 4.3% | — | Bosdev Bosclassifieds Classified ADS | 12/7/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via a URL in the insPath parameter to (1) index.php, (2) recent.php, (3) account.php, (4) classified.php, or (5) search.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Deltascripts PHP Classifieds | 30/6/2006 | 16/6/2026 | SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter. | |
| Modificada | Media (6.8) | 1.5% | — | Deltascripts PHP Classifieds | 30/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php. | |
| Modificada | Media (4.3) | 1.2% | — | Cescripts CAR Classifieds | 19/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Car Classifieds allows remote attackers to inject arbitrary web script or HTML via the make_id parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Locazolist Classifieds | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid parameter. | |
| Modificada | Baja (2.6) | 2.3% | 💥 Exploit | Unclassified Newsboard | 16/5/2006 | 16/6/2026 | Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is… | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Unclassified Newsboard | 16/5/2006 | 16/6/2026 | Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the ABBC[Config][smileset] parameter to… |