Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.1)0.25%—Ceviz Informatics INC WEB DesignAI28/8/202631/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.
AplazadaMedia (6.1)0.25%—Webbeyaz WEB Design Medikum WEBAI8/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
AplazadaCrítica (9.8)0.47%—Webbeyaz WEB Design Medikum WEBAI8/7/20269/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
AnalizadaAlta (8.4)0.12%—Google WEB Designer27/2/202617/6/2026
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
AplazadaAlta (7.1)0.25%—Vizly WEB Design Real Estate PackagesAI19/9/202530/9/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web Design Real Estate Packages allows Content Spoofing, CAPEC - 593 - Session Hijacking, CAPEC - 591 - Reflected XSS. This issue affects Real Estate Packages: before 5.1.
AplazadaAlta (7.1)0.20%—Dokuzsoft Technology E-commerce WEB Design ProductAI17/9/202525/9/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology E-Commerce Web Design Product allows XSS Through HTTP Headers. This issue affects E-Commerce Web Design Product: before 11.08.2025.
AplazadaMedia (5.9)0.20%—CWD WEB Designer Easy Elements HiderAI4/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CWD Web Designer Easy Elements Hider easy-elements-hider allows Stored XSS.This issue affects Easy Elements Hider: from n/a through <= 2.0.
AnalizadaAlta (7.1)0.59%—Google WEB Designer12/6/202517/6/2026
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template
AnalizadaAlta (7.8)0.16%—Google WEB Designer12/5/202517/6/2026
Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature
AplazadaAlta (7.1)0.44%—LDD WEB Design LDD Directory LiteAI13/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LDD Web Design LDD Directory Lite ldd-directory-lite allows Reflected XSS.This issue affects LDD Directory Lite: from n/a through <= 3.3.
AplazadaAlta (7.1)0.35%—Pulsar WEB Design Weekly Class ScheduleAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pulsar Web Design Weekly Class Schedule allows Reflected XSS.This issue affects Weekly Class Schedule: from n/a through 3.19.
ModificadaMedia (4.8)0.42%—Theweb-designs TWB Woocommerce14/11/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abu Bakar TWB Woocommerce Reviews plugin <= 1.7.5 versions.
ModificadaMedia (5.4)0.36%—WEB Design Easy Sign UP Project WEB Design Easy Sign UP10/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Andrew @ Geeenville Web Design Easy Sign Up plugin <= 3.4.1 versions.
ModificadaAlta (7.5)1.00%—WEB Design Hero Joomladate10/2/200916/6/2026
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a viewProfile action to index.php.
ModificadaMedia (6.8)1.8%—Pensacola WEB Designs Xtremeasp Photogallery17/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary HTML or web script via (1) the catname parameter to displaypic.asp or (2) the search field. NOTE: vector 1 likely overlaps CVE-2006-3032.
ModificadaAlta (7.5)1.2%—Pensacola WEB Designs Xtremeasp Photogallery17/1/200716/6/2026
SQL injection vulnerability in displaypic.asp in Xtreme ASP Photo Gallery allows remote attackers to inject arbitrary SQL commands via the sortorder parameter.
ModificadaMedia (4.3)1.3%—Pensacola WEB Designs Xtreme ASP Photo Gallery15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp.
ModificadaAlta (7.5)2.0%—OUT OF THE Trees WEB Design Selectapix9/6/200616/6/2026
Multiple SQL injection vulnerabilities in SelectaPix 1.31 allow remote attackers to execute arbitrary SQL commands via the (1) albumID parameter to (a) view_album.php or (b) index.php, (2) imageID parameter to (c) popup.php, or (3) username and (4) password parameters to (d) admin/member.php.
ModificadaBaja (2.6)2.1%—OUT OF THE Trees WEB Design Selectapix9/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in SelectaPix 1.31 allows remote attackers to inject arbitrary web script or HTML via the albumID parameter to (1) popup.php and (2) view_album.php.
ModificadaAlta (7.5)1.1%—OUT OF THE Trees WEB Design Selectapix1/6/200616/6/2026
SQL injection vulnerability in view_album.php in SelectaPix 1.4 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party sources.
ModificadaMedia (5)1.3%—OUT OF THE Trees WEB Design Selectapix19/5/200616/6/2026
view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter.
ModificadaAlta (7.5)3.0%—Pensacola WEB Designs Xtremeasp Photogallery31/12/200416/6/2026
SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.