Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 2.4% | 💥 Exploit | Torrenttrader Classic | 22/6/2009 | 16/6/2026 | Directory traversal vulnerability in backend/admin-functions.php in TorrentTrader Classic 1.09, when used on a case-insensitive web site, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ss_uri parameter, in conjunction with a modified component name. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Torrenttrader Classic | 22/6/2009 | 16/6/2026 | TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function; and allows remote attackers to (2) obtain other potentially sensitive information via a direct request to check.php. | |
| Modificada | Media (6.4) | 2.7% | 💥 Exploit | Torrenttrader Classic | 22/6/2009 | 16/6/2026 | backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and download a backup database by making a direct request and then retrieving a .gz file from backups/. | |
| Modificada | Media (6.5) | 1.7% | 💥 Exploit | Torrenttrader Classic | 22/6/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitrary SQL commands via (1) the origmsg parameter to account-inbox.php; the categ parameter to (2) delreq.php and (3) admin-delreq.php; (4) the choice parameter to index.php; (5) the id parameter to… | |
| Modificada | Baja (3.5) | 1.5% | 💥 Exploit | Torrenttrader Classic | 22/6/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Title field to requests.php, related to viewrequests.php; and (2) the Torrent Name field to torrents-upload.php, related to the logging of torrent… | |
| Modificada | Media (6.8) | 1.2% | — | Torrenttrader Classic | 18/6/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in TorrentTrader 1.08 Classic allow remote attackers to execute arbitrary SQL commands via the (1) email or (2) wantusername parameter to account-signup.php, or the (3) receiver parameter to account-inbox.php in a msg action. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | TorrenttraderTorrenttrader Classic | 6/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Media (4.3) | 0.52% | — | TorrenttraderTorrenttrader Classic | 6/3/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerabilities in account-inbox.php in TorrentTrader Classic 1.08 allow remote attackers to perform certain actions as other users, as demonstrated by sending messages. |