Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.5% | — | Ajsquare AJ Auction Pro-oopd | 25/8/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via the txtkeyword parameter in a search action. | |
| Modificada | Alta (7.5) | 0.99% | — | Ajsquare AJ Auction Pro-oopd | 16/9/2009 | 16/6/2026 | SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | AJ Square AJ Auction | 13/8/2009 | 16/6/2026 | AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass authentication via a direct request to admin/user.php. | |
| Modificada | Alta (7.5) | 2.6% | — | AJ Square AJ Auction | 13/8/2009 | 16/6/2026 | AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when certain scripts are called directly, which allows remote attackers to bypass authentication via a direct request to (1) site.php, (2) auction.php, (3) mail.php, (4) fee_setting.php, (5) earnings.php,… | |
| Modificada | Alta (7.5) | 1.00% | — | AJ Square AJ Auction | 6/3/2009 | 16/6/2026 | SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | AJ Square AJ Auction | 28/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via the product parameter. | |
| Modificada | Alta (7.5) | 0.93% | — | AJ Square AJ Auction | 28/1/2009 | 16/6/2026 | SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute arbitrary SQL commands via the seller_id parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | AJ Square AJ Auction | 24/11/2008 | 16/6/2026 | SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the item_id parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | AJ Square AJ Auction | 25/6/2008 | 16/6/2026 | SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter. |