Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.54% | — | Noah Hearle WE RE OpenAIDesignextreme WE RE OpenAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Noah Hearle, Design Extreme We’re Open! allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects We’re Open!: from n/a through 1.45. | |
| Aplazada | Media (5.4) | 0.52% | — | Noah Hearle Reviews AND Rating Google MY BusinessAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Noah Hearle, Design Extreme Reviews and Rating – Google My Business allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reviews and Rating – Google My Business: from n/a through 4.14. | |
| Aplazada | Media (5.9) | 0.34% | — | Noahkagan UnderconstructionAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan underConstruction allows Stored XSS.This issue affects underConstruction: from n/a through 1.21. | |
| Modificada | Media (5.4) | 0.33% | — | Noahkagan Scroll Triggered BOX | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll Triggered Box allows Stored XSS.This issue affects Scroll Triggered Box: from n/a through 2.3. | |
| Modificada | Media (4.3) | 1.1% | — | Nordicwind NoahNordicwind Document Management System | 20/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Nordicwind Document Management System (NOAH) before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Noah | 30/11/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in PHP Content Architect (aka NoAh) 0.9 pre 1.2 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the filepath parameter to (1) css_file.php, (2) js_file.php, or (3) xml_file.php in noah/modules/nosystem/templates/. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Noah | 9/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect, phparch) 0.9 pre 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tpls[1] parameter. | |
| Modificada | Alta (10) | 3.6% | 💥 Exploit | Noah Spurrier Upload Tool FOR PHP | 6/3/2007 | 16/6/2026 | Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 1.3% | — | Phpoutsourcing Noahs Classifieds | 16/10/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PhpOutsourcing Noah's Classifieds 1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the frommethod parameter. | |
| Modificada | Media (6.4) | 1.6% | — | Phpoutsourcing Noahs Classifieds | 21/3/2006 | 16/6/2026 | Noah's Classifieds 1.3 and earlier allows remote attackers to obtain sensitive information via an invalid list parameter in the showdetails method to index.php, which reveals the path in an error message. | |
| Modificada | Media (6.8) | 1.4% | — | Phpoutsourcing Noahs Classifieds | 21/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) method or (2) list parameter. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php. | |
| Modificada | Media (5) | 1.5% | — | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Noah's Classifieds 1.3 allows remote attackers to obtain the installation path via a direct request to include files, as demonstrated by classifieds/gorum/category.php. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 24/2/2006 | 16/6/2026 | SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors. | |
| Modificada | Media (5) | 2.9% | — | Noah Medling Rcblog | 22/1/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrator's account name and password, via a .. (dot dot) in the post parameter. | |
| Modificada | Media (5) | 1.8% | — | Noah Medling Rcblog | 22/1/2006 | 16/6/2026 | Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 password hashes. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 20/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpoutsourcing Noahs Classifieds | 20/9/2005 | 16/6/2026 | SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter. | |
| Modificada | Alta (7.5) | 2.7% | — | Noah Gray Graymatter | 25/6/2002 | 16/6/2026 | Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server… |