Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3042▲ 562 respecto a la semana anterior
Críticas / altas1454▲ 281 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 8.6% | — | Phpcompta/noalyss | 6/10/2014 | 17/6/2026 | backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter. | |
| Modificada | Media (5) | 2.9% | — | Bernhard Frohlich Phpcom | 11/6/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) file parameter to module/admin/files/show_file.php and the (2) path parameter to module/admin/files/show_source.php. | |
| Modificada | Media (4.3) | 1.1% | — | Bernhard Frohlich Phpcom | 11/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in templates/1/login.php in phpCommunity 2 2.1.8 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Bernhard Frohlich Phpcom | 11/6/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunity 2 2.1.8, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the forum_id parameter in a forum action to index.php, (2) the topic_id parameter in a forum action to index.php, (3) the wert parameter in an id search… | |
| Modificada | Alta (7.5) | 0.93% | — | Phpcompet.free PHP Competition System | 21/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Phpcomasy | 20/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in phpComasy 0.9.1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter. | |
| Modificada | Alta (7.5) | 0.93% | — | Phpcomasy | 5/3/2008 | 16/6/2026 | SQL injection vulnerability in index.php in phpComasy 0.8 allows remote attackers to execute arbitrary SQL commands via the mod_project_id parameter in a project_detail action. | |
| Modificada | Alta (7.5) | 3.2% | — | Myphpcommander | 30/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the gl_root parameter. | |
| Modificada | Media (6.8) | 1.4% | — | Phpcomasy | 10/11/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpComasy CMS 0.7.9pre and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username or (2) password parameters. | |
| Modificada | Alta (7.5) | 2.6% | — | Szewo Phpcommander | 8/9/2006 | 16/6/2026 | Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code. | |
| Modificada | Media (6.8) | 2.2% | — | Phpcommunitycalendar | 3/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php. | |
| Modificada | Alta (7.5) | 2.1% | — | Phpcommunitycalendar | 3/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4)… | |
| Modificada | Alta (7.5) | 1.2% | — | Phpcomasy | 22/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php in phpComasy 0.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: an examination of the 0.7.5 source code suggests that there is no id parameter being handled directly by index.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to execute arbitrary SQL commands via the (1) login field in login.php or (2) LocationID parameter to week.php. | |
| Modificada | Media (4.3) | 1.3% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the LocationID parameter to (1) thankyou.php or (2) day.php, font parameter to (3) calDaily.php, (4) calMonthly.php, (5) calMonthlyP.php,… | |
| Modificada | Alta (7.5) | 1.8% | — | Phpcommunitycalendar | 14/9/2005 | 16/6/2026 | phpCommunityCalendar 4.0.3 allows remote attackers to bypass authentication and gain unauthorized access via a direct request to the admin directory. |