Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 8.3% | 💥 Exploit | Snipegallery Snipe Gallery | 1/6/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_admin_path parameter to (1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php, (6) admin/gallery/index.php, (7) admin/gallery/view.php, (8)… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Electrictoad Snippetmaster Webpage Editor | 11/2/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_PATH] parameter to includes/vars.inc.php and the (2) g_pcltar_lib_dir parameter to includes/tar_lib/pcltar.lib.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Electrictoad Snippetmaster Webpage Editor | 11/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter. | |
| Modificada | Alta (7.5) | 48% | 💥 Exploit | Wordpress Sniplets Plugin | 28/2/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter. | |
| Modificada | Alta (7.5) | 44% | 💥 Exploit | Wordpress Sniplets Plugin | 28/2/2008 | 16/6/2026 | Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter. | |
| Modificada | Media (4.3) | 7.4% | 💥 Exploit | Wordpress Sniplets Plugin | 28/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and possibly (d) modules/execute.php; the (2) url… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Xoops Wf-snippets | 11/4/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the c parameter in a cat action. | |
| Modificada | Media (4.3) | 1.6% | — | Snipegallery Snipe Gallery | 18/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Snipegallery Snipe Gallery | 14/12/2005 | 16/6/2026 | SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Snipegallery Snipe Gallery | 14/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | PHP Code Snippet Library | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbitrary web script or HTML via the (1) cat_select or (2) show parameters. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Snipsnap | 31/12/2004 | 16/6/2026 | CRLF injection vulnerability in SnipSnap 0.5.2a, and other versions before 1.0b1, allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server. |