Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.39% | — | Conlabz Gmbh WP BookmarksAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in conlabz GmbH WP Bookmarks wp-bookmarks allows Reflected XSS.This issue affects WP Bookmarks: from n/a through <= 1.1. | |
| Modificada | Media (6.8) | 1.1% | — | Shareaholic Sexybookmarks | 8/8/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows remote attackers to hijack the authentication of users for requests that "manipulate plugin settings." | |
| Modificada | Alta (7.5) | 1.2% | — | Coldgen Coldbookmarks | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in index.cfm in ColdGen ColdBookmarks 1.22 allows remote attackers to execute arbitrary SQL commands via the BookmarkID parameter in an EditBookmark action. | |
| Modificada | Alta (7.5) | 2.3% | — | Brian Wilson Ol'bookmarks | 6/3/2009 | 16/6/2026 | Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the show parameter. | |
| Modificada | Alta (7.5) | 0.94% | — | Brian Wilson Ol'bookmarks | 6/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action. | |
| Modificada | Alta (7.5) | 2.3% | — | Brian Wilson Ol'bookmarks | 6/3/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary PHP code via a URL in the framefile parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Brian Wilson Ol'bookmarks | 6/3/2009 | 16/6/2026 | Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the framefile parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Quidascript Bookmarks Favourites Script | 30/1/2009 | 16/6/2026 | SQL injection vulnerability in view_group.php in QuidaScript BookMarks Favourites Script (APB) allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Lbstone Active PHP BookmarksLbstone APB | 21/8/2008 | 16/6/2026 | SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | OL Bookmarks | 22/5/2007 | 16/6/2026 | SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 10% | — | OL Bookmarks | 22/5/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP code via a URL in the root parameter to (1) test1.php, (2) blackorange.php, (3) default.php, (4) frames1.php, (5) frames1_top.php, (7) test2.php, (8) test3.php, (9) test4.php, (10) test5.php, (11)… | |
| Modificada | Alta (7.5) | 2.7% | — | Socketwiz Bookmarks | 2/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the root_dir parameter. | |
| Modificada | Media (6.8) | 1.9% | — | Stefan Frech Online-bookmarks | 7/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Stefan Frech Online-bookmarks | 7/12/2006 | 16/6/2026 | SQL injection vulnerability in the login function in auth.inc in Stefan Frech online-bookmarks 0.6.12 allows remote attackers to execute arbitrary SQL commands via the (1) username and possibly the (2) password parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.8% | — | Active PHP Bookmarks | 29/11/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in L. Brandon Stone and Nathanial P. Hendler Active PHP Bookmarks (APB) 1.1.02 allow remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS['apb_path'] parameter in (1) apb_common.php or (2) apb.php. NOTE: CVE and another third party dispute this… | |
| Modificada | Media (4.3) | 1.2% | — | Nukebookmarks | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NukeBookmarks 0.6 for PHP-Nuke allow remote attackers to inject arbitrary web script or HTML via the (1) catname, (2) markname, (3) comment, or (4) category parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Nukebookmarks | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (5) | 1.4% | — | Nukebookmarks | 26/3/2005 | 16/6/2026 | marks.php in NukeBookmarks 0.6 for PHP-Nuke allows remote attackers to obtain sensitive information via an invalid (1) file or (2) category parameter, which reveal the path in an error message. | |
| Modificada | Alta (7.5) | 1.6% | — | Stefan Frech Online-bookmarksAI | 31/12/2004 | 16/6/2026 | Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php. | |
| Modificada | Media (6.4) | 1.5% | — | Active PHP Bookmarks | 31/12/2003 | 16/6/2026 | add_bookmark.php in Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to add arbitrary bookmarks as other users using a modified auth_user_id parameter. | |
| Modificada | Media (5) | 1.4% | — | Active PHP BookmarksAI | 31/12/2003 | 16/6/2026 | Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code. |