Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▲ 27 respecto a la semana anterior
Críticas / altas1477▲ 294 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.8% | — | Smartisoft Phpbazar | 17/6/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Smartisoft Phpbazar | 7/12/2009 | 16/6/2026 | phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to the admin control panel via a direct request. | |
| Modificada | Alta (7.5) | 0.99% | — | Smartisoft Phpbazar | 7/12/2009 | 16/6/2026 | SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-3767. | |
| Modificada | Alta (7.5) | 1.00% | — | Smartisoft Phpbazar | 22/8/2008 | 16/6/2026 | SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter. | |
| Modificada | Alta (7.5) | 3.3% | — | Smartisoft Phpbazar | 22/5/2006 | 16/6/2026 | Admin/admin.php in phpBazar 2.1.0 and earlier allows remote attackers to bypass the authentication process and gain unauthorized access to the administrative section by setting the action parameter to edit_member and the value parameter to 1. | |
| Modificada | Media (6.4) | 3.0% | — | Smartisoft Phpbazar | 22/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in classified_right.php in phpBazar 2.1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter. |