Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
224 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Ftls Guestbook | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) name, or (3) title field. | |
| Modificada | Media (4.3) | 1.1% | — | Filebased Guestbook | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gbook.php in Filebased guestbook 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the comment section. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Eternalmart Guestbook | 31/12/2003 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the emgb_admin_path parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Nukedweb Guestbookhost | 31/12/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NukedWeb GuestBookHost allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Email and (3) Message fields when signing the guestbook. | |
| Modificada | Media (4.3) | 1.1% | — | Justice Media Guestbook | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables. | |
| Modificada | Media (4.3) | 1.6% | — | CGI City CC Guestbook | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cc_guestbook.pl in CGI City CC GuestBook allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) homepage_title (webpage title) parameters. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Planetmoon Guestbook | 31/12/2003 | 16/6/2026 | PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin script password, and other passwords, via a direct request to files/passwd.txt. | |
| Modificada | Media (4.3) | 1.3% | — | Levcgi.com Myguestbook | 31/12/2003 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in (1) admin_index.php, (2) admin_pass.php, (3) admin_modif.php, and (4) admin_suppr.php in MyGuestbook 3.0 allows remote attackers to execute arbitrary PHP code by modifying the location parameter to reference a URL on a remote web server that contains file.php via script… | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Justice Media Guestbook | 31/12/2003 | 16/6/2026 | Justice Guestbook 1.3 allows remote attackers to obtain the full installation path via a direct request to cfooter.php3, which leaks the path in an error message. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | MPM Guestbook | 3/11/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter. | |
| Modificada | Media (4.3) | 5.0% | 💥 Exploit | CHI Kien Uong Guestbook | 23/10/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web script or HTML via (1) HTML in a posted message or (2) Javascript in an onmouseover attribute in an e-mail address or URL. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | BEN Chivers GuestbookEasy Scripts Archive Easy Guestbook | 11/4/2003 | 16/6/2026 | Easy Guestbook CGI programs do not authenticate the administrator, which allows remote attackers to (1) delete entries via direct access of admin.cgi, or (2) reconfigure Guestbook via direct access of config.cgi. | |
| Modificada | Media (6.8) | 1.3% | — | Aspjar Guestbook | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in ASPjar Guestbook 1.00 allows remote attackers to execute arbitrary script as other users via the "web site" parameter in a guestbook message. | |
| Modificada | Media (5) | 1.4% | — | Aspjar Guestbook | 31/12/2002 | 16/6/2026 | ASPjar Guestbook 1.00 allows remote attackers to delete arbitrary messages accessing the delete.asp administrative script with certain cookie values set to "true". | |
| Modificada | Alta (7.5) | 2.2% | — | Cgiscript Csguestbook | 31/12/2002 | 16/6/2026 | csGuestbook.cgi in CGISCRIPT.NET csGuestbook 1.0 allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. | |
| Modificada | Alta (7.6) | 2.1% | — | BG Guestbook | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in signgbook.php for BG GuestBook 1.0 allows remote attackers to execute arbitrary Javascript via encoded tags such as <, >, and & in fields such as (1) name, (2) email, (3) AIM screen name, (4) website, (5) location, or (6) message. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Levcgi.com Myguestbook | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML via fields such as (1) user name or (2) comments. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Philip Chinerys Guestbook | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute Javascript or HTML via fields such as (1) Name, (2) EMail, or (3) Homepage. | |
| Modificada | Alta (7.5) | 3.6% | — | GCF Dynamic Guestbook | 3/7/2002 | 16/6/2026 | Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter. | |
| Modificada | Alta (7.5) | 3.6% | — | GCF Dynamic Guestbook | 3/7/2002 | 16/6/2026 | Cross-site scripting vulnerability in Dynamic Guestbook 3.0 allows remote attackers to execute code in clients who access guestbook pages via the parameters (1) name, (2) mail, or (3) kommentar. | |
| Modificada | Alta (7.5) | 85% | 💥 Exploit | Apache Http ServerMatt Wright Guestbook | 13/9/1999 | 16/6/2026 | guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->". | |
| Modificada | Alta (7.5) | 6.2% | 💥 Exploit | Webcom CGI Guestbook | 9/4/1999 | 16/6/2026 | Vulnerability in the Wguest CGI program. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Webcom CGI Guestbook | 1/4/1999 | 16/6/2026 | The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter. | |
| Modificada | Alta (7.5) | 3.3% | — | Webcom CGI Guestbook | 1/9/1997 | 16/6/2026 | Remote execution of arbitrary commands through Guestbook CGI program. |