Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.50% | — | Simplephpscripts Classified ADS Script PHP | 29/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file user.php of the component HTTP POST Request Handler. The manipulation of the argument title leads to cross site scripting. The attack can… | |
| Modificada | Media (6.1) | 0.50% | — | Simplephpscripts Classified ADS Script PHP | 29/6/2023 | 17/6/2026 | A vulnerability was found in SimplePHPscripts Classified Ads Script 1.8. It has been classified as problematic. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation of the argument p leads to cross site scripting. It is possible to launch the attack… | |
| Modificada | Media (6.1) | 0.85% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected Cross-Site Scripting (XSS) via the Search field. | |
| Modificada | Media (6.5) | 1.4% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has directory traversal via a direct request for a listing of an uploads directory. | |
| Modificada | Media (5.3) | 1.0% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 21/3/2019 | 17/6/2026 | PHP Scripts Mall Opensource Classified Ads Script 3.2.2 has reflected HTML injection via the Search Form. | |
| Modificada | Crítica (9.8) | 3.0% | — | Opensource Classified ADS Script Project Opensource Classified ADS Script | 13/12/2017 | 17/6/2026 | Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. | |
| Modificada | Baja (3.5) | 0.95% | — | Osinet Classified ADS | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the administration user interface in the Classified Ads module before 6.x-3.1 and 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a category name. | |
| Modificada | Alta (7.5) | 3.0% | — | Sepcity Classified ADS | 17/2/2009 | 16/6/2026 | SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 0.97% | — | Sepcity Classified ADS | 16/2/2009 | 16/6/2026 | SQL injection vulnerability in classdis.asp in SepCity Classified Ads allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Pozscripts Classified ADS | 13/8/2008 | 16/6/2026 | SQL injection vulnerability in browsecats.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3672. | |
| Modificada | Alta (7.5) | 0.91% | — | Pozscripts Classified ADS | 13/8/2008 | 16/6/2026 | SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3673. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.0% | — | Hoffice Smart Classified ADSHoffice Smart Photo ADSHoffice Smart Photo ADS Gold | 15/4/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in view.cgi in Smart Classified ADS Professional, Smart Photo ADS, and Smart Photo ADS Gold allow remote attackers to inject arbitrary web script or HTML via the (1) AdNum and (2) Department parameters. NOTE: the provenance of this information is unknown; the details… | |
| Modificada | Media (4.3) | 1.0% | — | Bosdev Bosclassifieds Classified ADS | 10/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in account.php in BosClassifieds Classified Ads System 3.0 allows remote attackers to inject arbitrary web script or HTML via the returnTo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 4.3% | — | Bosdev Bosclassifieds Classified ADS | 12/7/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BosClassifieds Classified Ads allow remote attackers to execute arbitrary PHP code via a URL in the insPath parameter to (1) index.php, (2) recent.php, (3) account.php, (4) classified.php, or (5) search.php. | |
| Modificada | Alta (10) | 4.2% | — | Usanet Creations Domain Name AuctionUsanet Creations Makebid Auction DeluxeUsanet Creations Makebid Auction StandardUsanet Creations Makebid Reverse Auction+2 | 13/7/2005 | 16/6/2026 | The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the… |