Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.41% | — | E-learning PHP ScriptAI | 30/1/2026 | 17/6/2026 | e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information. | |
| Aplazada | Media (5.1) | 0.40% | — | Pharmacy POS PHP ScriptAI | 16/7/2025 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the u_medicine_name parameter in /edit_medicine.php. This vulnerability can be exploited to steal sensitive… | |
| Modificada | Crítica (9.8) | 1.7% | — | Superstorefinder PHP Script | 14/9/2023 | 17/6/2026 | SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter. | |
| Modificada | Media (6.1) | 0.36% | — | Gzscripts CAR Rental PHP Script | 19/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in GZ Scripts Car Rental Script 1.8. Affected is an unknown function of the file /EventBookingCalendar/load.php?controller=GzFront/action=checkout/cid=1/layout=calendar/show_header=T/local=3. The manipulation of the argument… | |
| Modificada | Crítica (9.8) | 1.2% | — | KB Messages PHP Script Project KB Messages PHP Script | 13/7/2022 | 17/6/2026 | A vulnerability has been found in KB Messages PHP Script 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 3.0% | — | Domainsale PHP Script Project Domainsale PHP Script | 13/12/2017 | 17/6/2026 | DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter. | |
| Modificada | Crítica (9.8) | 2.7% | — | Arox School ERP PHP Script | 31/10/2017 | 17/6/2026 | AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. | |
| Modificada | Media (6.8) | 2.3% | — | Phpscriptlerim PHP Scriptlerim Who's WHO | 17/11/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the authentication of administrators or requests that (1) add an admin account via a request to filepath/yonetim/plugin/adminsave.php or have unspecified impact via a request to (2)… | |
| Modificada | Alta (7.5) | 1.2% | — | Real-estate-php-script Real Estate PHP Script | 23/9/2013 | 16/6/2026 | SQL injection vulnerability in property_listings_detail.php in Real Estate PHP Script allows remote attackers to execute arbitrary SQL commands via the listingid parameter. | |
| Modificada | Media (4.3) | 0.98% | — | Real-estate-php-script Real Estate PHP Script | 23/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search_residential.php in Real Estate PHP Script allows remote attackers to inject arbitrary web script or HTML via the bos parameter. | |
| Modificada | Media (5) | 2.8% | — | Php4scripte Gastebuch | 12/9/2011 | 16/6/2026 | Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter. | |
| Modificada | Alta (7.5) | 5.6% | — | Moviephp Movie PHP Script | 6/5/2010 | 16/6/2026 | Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter. | |
| Modificada | Alta (7.5) | 2.9% | — | Sansuart Free Simple Guestbook PHP Script | 11/8/2009 | 16/6/2026 | Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded before 20081111, allows remote attackers to inject arbitrary PHP code into messages.txt via the message parameter to act.php, which is executed when guestbook/guestbook.php is accessed. NOTE: some… | |
| Modificada | Alta (7.5) | 2.6% | — | Marc Melvin A+ PHP Scripts News Management System | 8/4/2009 | 16/6/2026 | A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1. | |
| Modificada | Alta (7.5) | 1.2% | — | Seraphimtech Free Bible Search PHP Script | 29/1/2009 | 16/6/2026 | SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | E-topbiz Number Links 1 PHP Script | 31/12/2008 | 16/6/2026 | SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action. | |
| Modificada | Media (4.3) | 1.2% | — | Simple PHP Scripts Gallery | 31/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 0.87% | — | Simple PHP Scripts Blog | 31/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in complete.php in Simple PHP Scripts blog 0.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | — | E-php Scripts B2B Trading Marketplace Script | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute arbitrary SQL commands via the cid parameter in a product action. | |
| Modificada | Alta (7.5) | 3.0% | — | Raven PHP Scripts Keep IT Simple Guest Book | 2/4/2008 | 16/6/2026 | Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected. | |
| Modificada | Media (4.3) | 2.0% | — | Justin Hagstrom Autoindex PHP Script | 15/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Justin Hagstrom AutoIndex PHP Script before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). | |
| Modificada | Alta (7.8) | 8.5% | — | Justin Hagstrom Autoindex PHP Script | 15/11/2007 | 16/6/2026 | classes/Url.php in Justin Hagstrom AutoIndex PHP Script before 2.2.4 allows remote attackers to cause a denial of service (CPU and memory consumption) via a %00 sequence in the dir parameter to index.php, which triggers an erroneous "recursive calculation." | |
| Modificada | Media (6.8) | 1.3% | — | Simple PHP Scripts Gallery | 15/5/2007 | 16/6/2026 | PHP file inclusion vulnerability in index.php in Ivan Peevski gallery 0.3 in Simple PHP Scripts (sphp) allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the gallery parameter, which is accessed by the file_exists function. NOTE: the provenance of this… | |
| Modificada | Alta (7.5) | 1.1% | — | Free PHP Scripts Schoolboard | 11/5/2007 | 16/6/2026 | SQL injection vulnerability in admin.php in SchoolBoard allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: CVE disputes this issue, because 'username' does not exist, and the password is not used in any queries | |
| Modificada | Alta (7.5) | 2.4% | — | Free PHP Scripts Free Image Hosting | 27/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in frontpage.php in Free Image Hosting 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter. NOTE: the forgot_pass.php vector is already covered by CVE-2006-5670, and the login.php vector overlaps CVE-2006-5763. |