Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.99% | — | Galaxyscriptz Myphpauction | 5/10/2011 | 16/6/2026 | SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Phpauction | 19/8/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1. | |
| Modificada | Media (5) | 1.3% | — | Phpauction | 19/8/2009 | 16/6/2026 | phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. | |
| Modificada | Alta (7.5) | 0.97% | — | Phpauctions | 8/4/2009 | 16/6/2026 | SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different vector than CVE-2009-0106. | |
| Modificada | Alta (7.5) | 2.6% | — | Phpauctions | 9/1/2009 | 16/6/2026 | PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies. | |
| Modificada | Media (4.3) | 1.5% | — | Phpauctions | 9/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Phpauctions | 9/1/2009 | 16/6/2026 | SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Phpauctions Phpauction GPL Enhanced | 6/8/2008 | 16/6/2026 | SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Phpauction | 27/6/2008 | 16/6/2026 | SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 38% | — | Phpauction GPL | 20/3/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in includes/. | |
| Modificada | Alta (7.5) | 3.2% | — | Gianluca Baldo PhpauctionPhpadsnew | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Gianluca Baldo Phpauction | 13/7/2005 | 16/6/2026 | SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description. | |
| Modificada | Media (6.4) | 1.5% | — | Gianluca Baldo Phpauction | 13/7/2005 | 16/6/2026 | Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Gianluca Baldo Phpauction | 13/7/2005 | 16/6/2026 | PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID. | |
| Modificada | Media (4.3) | 0.99% | — | Gianluca Baldo Phpauction | 13/7/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there is evidence that viewnews.php and login.php may not be part of… | |
| Modificada | Alta (7.5) | 2.8% | — | Gianluca Baldo Phpauction | 4/10/2002 | 16/6/2026 | login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table. |