Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.39% | — | Premai-io PremsqlAI | 5/4/2026 | 24/7/2026 | A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.py. This manipulation of the argument result causes code injection. The attack is possible to be carried out remotely. The exploit has been made available to the public… | |
| Modificada | Alta (7.5) | 1.6% | — | Cmsqlite | 27/5/2010 | 16/6/2026 | Directory traversal vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Cmsqlite | 27/5/2010 | 16/6/2026 | SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Hughes Technologies W3-msql | 8/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI. | |
| Modificada | Baja (2.1) | 0.33% | — | Hughes Msql | 26/12/2001 | 16/6/2026 | Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried. | |
| Modificada | Alta (10) | 9.9% | — | Hughes Msql | 27/12/1999 | 16/6/2026 | Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands. | |
| Modificada | Alta (7.5) | 5.3% | — | Hughes Msql | 17/8/1999 | 16/6/2026 | The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories. | |
| Modificada | Alta (7.5) | 1.4% | — | Hughes Msql | 15/2/1999 | 16/6/2026 | mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query. | |
| Modificada | Alta (7.5) | 3.0% | — | Hughes Msql | 1/1/1999 | 16/6/2026 | mSQL v2.0.1 and below allows remote execution through a buffer overflow. |