Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.89%—Owncloud Guests5/11/202517/6/2026
ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest user rather than a…
ModificadaMedia (5.4)0.51%—Nextcloud Guests18/1/202417/6/2026
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a permissions bypass. It is recommended that the…
ModificadaMedia (4.3)0.46%—Nextcloud Guests18/1/202417/6/2026
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no…
ModificadaAlta (7.5)2.5%—1byte Copy91byte Exactspy1byte Fonetracker1byte Guestspy+524/2/202217/6/2026
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
ModificadaAlta (7.5)1.3%—PHP Resource Voice OF WEB Allmyguests15/10/201417/6/2026
Multiple SQL injection vulnerabilities in Voice Of Web AllMyGuests 0.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) allmyphp_cookie cookie to admin.php or the (2) Username or (3) Password.
ModificadaMedia (4.3)0.99%—PHP Resource Voice OF WEB Allmyguests15/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the AMG_signin_topic parameter to index.php.
ModificadaAlta (7.5)0.97%—PHP Resource Voice OF WEB Allmyguests25/4/200816/6/2026
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary SQL commands via the AMG_id parameter in a comments action.
ModificadaAlta (7.5)5.0%—Allmyguests Project Allmyguests11/1/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.3.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the AMG_serverpath parameter to (1) comments.php and (2) signin.php; and possibly via a URL in unspecified parameters to (3) include/submit.inc.php, (4) admin/index.php,…
ModificadaAlta (7.5)4.0%—Allmyguests Project Allmyguests26/9/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _AMGconfig[cfg_serverpath] parameter in (1) modules/AllMyGuests/signin.php (aka the Nuke module) and (2) AllMyGuests/signin.php (aka the standalone).
ModificadaMedia (4.3)0.94%—Lars Ellingsen Guestserver14/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in guestbook.cgi in Lars Ellingsen Guestserver 4.13 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified message fields.
ModificadaCrítica (9.8)7.8%—Allmyguests Project AllmyguestsAllmylinks Project AllmylinksAllmyvisitors Project Allmyvisitors23/11/200416/6/2026
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyGuests allow remote attackers to execute arbitrary PHP code via a URL in the _AMVconfig[cfg_serverpath] parameter.
ModificadaAlta (7.5)3.6%—Seth Leonard Book OF GuestsSeth Leonard Post IT6/12/200116/6/2026
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.
ModificadaAlta (10)4.7%—Lars Ellingsen Guestserver3/5/200116/6/2026
Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.