Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 272 respecto a la semana anterior
Críticas / altas1349▲ 92 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.50% | — | AdodbAI | 5/8/2025 | 17/6/2026 | ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a sqlite3 database and calls the… | |
| Aplazada | Crítica (10) | 0.74% | — | AdodbAI | 1/5/2025 | 17/6/2026 | ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a query parameter may allow an attacker to execute arbitrary SQL statements when the code using ADOdb connects to a PostgreSQL database and calls pg_insert_id()… | |
| Modificada | Crítica (9.1) | 2.2% | — | Adodb Project AdodbDebian Linux | 25/1/2022 | 17/6/2026 | Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21. | |
| Modificada | Media (6.1) | 1.9% | — | Adodb Project Adodb | 12/5/2017 | 17/6/2026 | Cross-site scripting vulnerability in ADOdb versions prior to 5.20.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.0% | — | Adodb Project AdodbFedoraproject Fedora | 3/10/2016 | 17/6/2026 | The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting. | |
| Modificada | Media (5) | 1.4% | — | John LIM Adodb | 23/9/2011 | 16/6/2026 | John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tests/test-active-record.php and certain other files. | |
| Modificada | Media (6.8) | 28% | — | Adodb LiteCmsmadesimple CMS Made SimpleJournalnessOpen-realty+2 | 24/9/2007 | 16/6/2026 | Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter. | |
| Modificada | Media (5) | 1.5% | — | John LIM Adodb Date Library | 25/9/2006 | 16/6/2026 | The Date Library in John Lim ADOdb Library for PHP allows remote attackers to obtain sensitive information via a direct request for (1) server.php, (2) adodb-errorpear.inc.php, (3) adodb-iterator.inc.php, (4) adodb-pear.inc.php, (5) adodb-perf.inc.php, (6) adodb-xmlschema.inc.php, and (7) adodb.inc.php; files in… | |
| Modificada | Media (5.1) | 1.7% | — | John LIM Adodb | 7/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in adodb-postgres7.inc.php in John Lim ADOdb, possibly 4.01 and earlier, as used in Intechnic In-link 2.3.4, allows remote attackers to execute arbitrary PHP code via a URL in the ADODB_DIR parameter. | |
| Modificada | Media (4.3) | 6.0% | — | John LIM Adodb | 21/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF. | |
| Modificada | Media (5) | 2.9% | — | John LIM Adodb | 25/1/2006 | 16/6/2026 | SQL injection vulnerability in ADOdb before 4.71, when using PostgreSQL, allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors involving binary strings. | |
| Modificada | Alta (7.5) | 13% | — | John LIM AdodbMantisMediabeezMoodle+2 | 9/1/2006 | 16/6/2026 | The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the… | |
| Modificada | Alta (7.5) | 13% | — | John LIM AdodbMantisMoodlePostnuke Software Foundation Postnuke+1 | 9/1/2006 | 16/6/2026 | Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP… | |
| Modificada | Media (5) | 1.2% | — | John LIM Adodb | 31/12/2004 | 16/6/2026 | John Lim ADOdb Library for PHP before 4.23 allows remote attackers to obtain sensitive information via direct requests to certain scripts that result in an undefined value of ADODB_DIR, which reveals the installation path in an error message. |