Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.39%—Premai-io PremsqlAI5/4/202624/7/2026
A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.py. This manipulation of the argument result causes code injection. The attack is possible to be carried out remotely. The exploit has been made available to the public…
ModificadaAlta (7.5)1.6%—Cmsqlite27/5/201016/6/2026
Directory traversal vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
ModificadaAlta (7.5)1.1%—Cmsqlite27/5/201016/6/2026
SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.
ModificadaMedia (4.3)1.5%—Hughes Technologies W3-msql8/1/200816/6/2026
Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI.
ModificadaBaja (2.1)0.33%—Hughes Msql26/12/200116/6/2026
Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.
ModificadaAlta (10)9.9%—Hughes Msql27/12/199916/6/2026
Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.
ModificadaAlta (7.5)5.3%—Hughes Msql17/8/199916/6/2026
The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
ModificadaAlta (7.5)1.4%—Hughes Msql15/2/199916/6/2026
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.
ModificadaAlta (7.5)3.0%—Hughes Msql1/1/199916/6/2026
mSQL v2.0.1 and below allows remote execution through a buffer overflow.