Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.35% | — | PHP AddressbookAI | 3/2/2026 | 17/6/2026 | PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through the 'id' parameter. Attackers can inject crafted SQL statements with time delays to extract information by observing response times in the photo.php endpoint. | |
| Aplazada | Alta (7.1) | 0.21% | — | Samwilson AddressbookAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in samwilson Addressbook addressbook allows Stored XSS.This issue affects Addressbook: from n/a through <= 1.1.3. | |
| Modificada | Media (6.8) | 0.64% | — | Plaatsoft Addressbook | 25/7/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Addressbook module for Drupal 6.x-4.2 and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Alta (7.5) | 0.99% | — | B-elektro COM Addressbook | 1/11/2011 | 16/6/2026 | SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a contact action to index.php. | |
| Modificada | Alta (7.5) | 16% | — | B-elektro COM Addressbook | 19/4/2010 | 16/6/2026 | Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 0.96% | — | Coronamatrix Phpaddressbook | 1/9/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) parameters. | |
| Modificada | Media (4.3) | 1.1% | — | Coronamatrix Phpaddressbook | 7/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in CoronaMatrix phpAddressBook 2.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Coronamatrix Phpaddressbook | 16/4/2008 | 16/6/2026 | SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Coronamatrix Phpaddressbook | 25/3/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php and (2) install.php. NOTE: it was later reported that vector 1 is also present in 2.0. | |
| Modificada | Alta (7.5) | 3.0% | — | Sb-websoft Addressbook | 28/3/2007 | 16/6/2026 | Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module_name parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file. | |
| Modificada | Media (4.3) | 1.2% | — | Clemens Wacha PHP Iaddressbook | 31/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP iAddressBook before 0.96 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | — | Clemens Wacha PHP Iaddressbook | 29/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHP iAddressBook before 0.95 allows remote attackers to inject arbitrary web script or HTML via the cat_name parameter, related to adding a category. (categories field). NOTE: some details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | Widgetmonkey Php-addressbook | 11/12/2005 | 16/6/2026 | SQL injection vulnerability in view.php in PHP-addressbook 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. |