Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | Silurus Classifieds ScriptAI | 6/3/2026 | 17/6/2026 | Silurus Classifieds Script 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ID parameter. Attackers can send GET requests to wcategory.php with crafted SQL payloads in the ID parameter to extract database table… | |
| Modificada | Alta (7.5) | 0.76% | — | Itechscripts Classifieds Script | 16/7/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Itech Classifieds Script 7.27. Affected is an unknown function of the file /subpage.php. The manipulation of the argument scat with the input =51' AND 4941=4941 AND 'hoCP'='hoCP leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Crítica (9.8) | 15% | — | Cars-seller-auto-classifieds-script Project Cars-seller-auto-classifieds-script | 14/5/2021 | 17/6/2026 | The request_list_request AJAX call of the Car Seller - Auto Classifieds Script WordPress plugin through 2.1.0, available to both authenticated and unauthenticated users, does not sanitise, validate or escape the order_id POST parameter before using it in a SQL statement, leading to a SQL Injection issue. | |
| Modificada | Crítica (9.8) | 3.6% | — | Ambittechnologies Itech B2B ScriptAmbittechnologies Itech Business Networking ScriptAmbittechnologies Itech Caregiver ScriptAmbittechnologies Itech Classifieds Script+8 | 9/5/2019 | 17/6/2026 | Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script 5.27i and Tech Image Sharing Script 4.13i… | |
| Modificada | Alta (7.5) | 1.2% | — | Clscript Classifieds Script | 3/5/2010 | 16/6/2026 | SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitrary SQL commands via the hpId parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Tukanas Easyclassifieds Script | 15/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Tukanas Classifieds (aka EasyClassifieds) Script 1.0 allows remote attackers to execute arbitrary SQL commands via the b parameter. | |
| Modificada | Media (5) | 7.6% | — | Phpclassifiedsscript PHP Classifieds Script | 25/8/2009 | 16/6/2026 | Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql. | |
| Modificada | Media (4.3) | 1.3% | — | Classifiedphpscript PHP Open Classifieds Script | 17/8/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php. | |
| Modificada | Media (4.3) | 1.5% | — | Softbizscripts Classifieds Script | 27/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) radio parameter to showcategory.php, (2) msg parameter to advertisers/signinform.php, (3) radio parameter to gallery.php, (4) msg parameter to lostpassword.php,… | |
| Modificada | Media (4.3) | 1.4% | — | Softbizscripts Classifieds Script | 26/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.0% | — | Phpclassifiedsscript PHP Classifieds Script | 27/5/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL commands via the fatherID parameter to (1) browse.php and (2) search.php. |