Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.2% | — | Hiox Guest Book | 21/1/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in add.php in HIOX Guest Book (HGB) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name1, (2) email, or (3) cmt parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Hitronsoft Nasim Guest Book | 11/5/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (4.3) | 1.1% | — | UDO VON Eynern Modern Guest Book Commenting System | 17/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Modern Guestbook / Commenting System (ve_guestbook) extension 2.7.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | — | Ahmet Donmez Webeyes Guest Book | 5/6/2009 | 16/6/2026 | SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL commands via the mesajid parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | Raven PHP Scripts Keep IT Simple Guest Book | 2/4/2008 | 16/6/2026 | Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected. | |
| Modificada | Alta (7.5) | 8.7% | — | Hiox India Guest Book | 12/4/2007 | 16/6/2026 | Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP code via the Email field, which results in code execution through a direct request to gb.php. | |
| Modificada | Alta (7.5) | 2.2% | — | Keep IT Simple Guest Book | 27/12/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the Keep It Simple Guest Book (KISGB) allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_to_themes parameter in (a) authenticate.php, and the (2) default_path_for_themes parameter in (b) admin.php and (c) upconfig.php. | |
| Modificada | Media (6.8) | 2.1% | — | Keep IT Simple Guest Book | 27/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter. | |
| Modificada | Media (6.8) | 1.3% | — | James Barnsley JAB Guest Book | 7/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pbguestbook.php in JAB Guest Book allows remote attackers to inject arbitrary web script or HTML via the author parameter. | |
| Modificada | Media (6.8) | 1.1% | — | James Barnsley JAB Guest Book | 7/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in pbguestbook.php in JAB Guest Book 20061205 allow remote attackers to inject arbitrary web script or HTML via the (1) topic or (2) message parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | — | Techno Dreams Guest Book | 1/11/2006 | 16/6/2026 | SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to execute arbitrary SQL commands via the key parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Aspscriptz Guest Book | 7/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities submit.asp in ASPScriptz Guest Book 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) GBOOK_UNAME, (2) GBOOK_EMAIL, (3) GBOOK_CITY, (4) GBOOK_COU, (5) GBOOK_WWW, and (6) GBOOK_MESS form fields. | |
| Modificada | Media (4.3) | 1.2% | — | Techno Dreams Guest Book | 6/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Techno Dreams Guest Book allows remote attackers to inject arbitrary web script or HTML via certain comment fields in the "Sign Our GuestBook" page, probably the x_Comments parameter to guestbookadd.asp. | |
| Modificada | Media (6.8) | 1.4% | — | Hiox India Guest Book | 22/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Hiox Guestbook 3.1 allows remote attackers to inject arbitrary web script or HTML via the input forms for signing the guestbook. | |
| Modificada | Alta (7.5) | 1.6% | — | Techno Dreams Guest Book | 30/10/2005 | 16/6/2026 | SQL injection vulnerability in Techno Dreams Guest Book script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp. | |
| Modificada | Alta (7.5) | 1.7% | — | Gurgens Guest Book | 18/5/2005 | 16/6/2026 | Gurgens (GASoft) Guest Book 2.1 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and passwords. | |
| Modificada | Media (5) | 1.5% | — | Smartwebby Smart Guest Book | 31/12/2004 | 16/6/2026 | SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as the unencrypted username and password of the administrator's account. | |
| Modificada | Media (4.3) | 1.7% | — | WEB Fresh Fresh Guest Book | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary web script or HTML via the Name field. |