Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.26% | — | Onsite Internet Gmbh Auktion NG AuktionssoftwareAI | 23/9/2026 | 25/9/2026 | A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of the component Public Password Reset Endpoint. The manipulation of the argument email leads to cross site scripting. The attack is possible to be carried out… | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Mhproducts ERO Auktion | 29/12/2010 | 16/6/2026 | SQL injection vulnerability in item.php in Ero Auktion 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-0723. | |
| Modificada | Alta (7.5) | 1.6% | 💥 Exploit | Phpscripte24 PAY PER Watch & BID Auktions System | 7/5/2010 | 16/6/2026 | SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | |
| Modificada | Media (4.3) | 0.85% | — | Phpscripte24 PAY PER Watch & BID Auktions System | 7/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to inject arbitrary web script or HTML via the id_auk parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Phpscripte24 Niedrig Gebote PRO Auktions System II | 6/4/2010 | 16/6/2026 | SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers to execute arbitrary SQL commands via the id_auk parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Miethner-scripting DZ Erotik Auktionshaus V4rgo | 24/3/2010 | 16/6/2026 | SQL injection vulnerability in news.php in DZ EROTIK Auktionshaus V4rgo allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Scripteverkauf Domain Verkaus AND Auktions Portal | 16/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Mhproducts ERO Auktion | 26/2/2010 | 16/6/2026 | SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Mhproducts PHP Auktion PRO | 26/2/2010 | 16/6/2026 | SQL injection vulnerability in news.php in Php Auktion Pro allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Systemsoftware Auktionshaus Gelb | 26/2/2010 | 16/6/2026 | SQL injection vulnerability in news.php in Auktionshaus Gelb 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Systemsoftware Erotik Auktionshaus | 26/2/2010 | 16/6/2026 | SQL injection vulnerability in news.php in Erotik Auktionshaus allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | HIS Auktion | 2/6/2001 | 16/6/2026 | Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters. |