Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.5%💥 ExploitXigla Absolute News Manager.net14/7/200916/6/2026
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
ModificadaMedia (4.3)1.3%💥 ExploitVirtuenetz Virtue News Manager9/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
ModificadaAlta (7.5)1.0%💥 ExploitVirtuenetz Virtue News Manager9/6/200916/6/2026
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.
ModificadaAlta (7.5)1.0%💥 ExploitDreamlevels Dreamnews Manager16/7/200816/6/2026
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.5)1.2%—Xigla Absolute News Manager XE18/6/200816/6/2026
SQL injection vulnerability in search.asp in Xigla Absolute News Manager XE 3.2 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
ModificadaBaja (3.5)1.0%—Xigla Absolute News Manager XE18/6/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute News Manager XE 3.2 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) pblname and (2) text parameters to (a) admin/search.asp, (3) name parameter to (b) admin/publishers.asp, and other unspecified vectors…
ModificadaMedia (5)2.7%💥 ExploitNews Manager19/5/200816/6/2026
Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
ModificadaAlta (7.5)1.00%💥 ExploitNews Manager19/5/200816/6/2026
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.
ModificadaAlta (7.5)2.4%💥 ExploitNews Manager19/5/200816/6/2026
News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2) login/info.php.
ModificadaAlta (7.5)2.3%💥 ExploitAvalonnet News Manager19/5/200816/6/2026
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the read_xml_include parameter.
ModificadaMedia (4.3)2.3%💥 ExploitXigla Absolute News Manager.net7/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx.
ModificadaAlta (7.5)2.9%💥 ExploitXigla Absolute News Manager.net7/12/200716/6/2026
Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.
ModificadaMedia (5)2.7%💥 ExploitXigla Absolute News Manager.net7/12/200716/6/2026
Absolute News Manager.NET 5.1 allows remote attackers to obtain sensitive information via a direct request to getpath.aspx, which reveals the installation path in an error message.
ModificadaMedia (5)8.4%💥 ExploitXigla Absolute News Manager.net7/12/200716/6/2026
Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
ModificadaMedia (6.8)2.0%💥 ExploitNews Manager Deluxe26/4/200716/6/2026
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
ModificadaMedia (4.3)1.8%💥 ExploitBuilt2go News Manager Blog3/3/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.
ModificadaMedia (6.8)2.1%—Expinion.net Inews PublisherExpinion.net News Manager4/12/200616/6/2026
SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows remote attackers to execute arbitrary SQL commands via the ex parameter. NOTE: early reports of this issue reported it as XSS, but this was erroneous. The original report was for…
ModificadaAlta (7.5)1.4%💥 ExploitDotnetindex Active News Manager24/11/200616/6/2026
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by…
ModificadaAlta (7.5)3.7%💥 ExploitDotnetindex Active News Manager24/11/200616/6/2026
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query parameter to activenews_search.asp.
ModificadaMedia (4.3)1.9%💥 ExploitDotnetindex Active News Manager24/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter.
ModificadaMedia (6.4)2.9%💥 ExploitPRE Projects PRE News Manager2/6/200616/6/2026
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php.…
ModificadaMedia (5.8)2.8%—PRE Projects PRE News Manager31/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Pre News Manager 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and…
ModificadaAlta (7.5)1.3%—Dotnetindex Active News Manager31/5/200516/6/2026
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.
ModificadaAlta (7.5)1.2%—Darrel Oneil ASP Virtual News Manager11/5/200516/6/2026
SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.
ModificadaMedia (4.3)2.2%💥 ExploitExpinion.net News Manager Lite31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.
Orbitaley — Vulnerabilidades