Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

250 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.94%💥 ExploitGregory Kokanosky Phpmynewsletter12/3/200816/6/2026
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earlier allows remote attackers to execute arbitrary SQL commands via the msg_id parameter.
ModificadaAlta (7.5)2.6%💥 ExploitWordpress ST Newsletter Plugin12/2/200816/6/2026
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM NewsletterMambo COM NewsletterMambo31/1/200816/6/2026
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
ModificadaMedia (6.8)2.8%💥 ExploitNmnnewsletter28/12/200716/6/2026
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter.
ModificadaMedia (4.3)1.7%💥 ExploitOpen Newsletter10/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.
ModificadaMedia (6.8)0.95%💥 ExploitAlorys-hebergement KwsphpAlorys-hebergement Newsletter Module14/10/200716/6/2026
SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.
ModificadaAlta (7.5)62%💥 ExploitWanewsletter1/6/200716/6/2026
PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter.
ModificadaAlta (10)8.0%💥 ExploitGregory Kokanosky Phpmynewsletter30/4/200716/6/2026
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.
ModificadaAlta (10)8.2%💥 ExploitGregory Kokanosky Phpmynewsletter30/4/200716/6/2026
admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a…
ModificadaAlta (7.5)1.2%💥 ExploitActive WEB Softwares Active Newsletter27/3/200716/6/2026
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter.
ModificadaAlta (7.5)1.2%💥 ExploitMxmania Newsletter MX28/12/200616/6/2026
SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (7.5)4.3%💥 ExploitOpen Newsletter28/12/200616/6/2026
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability.
ModificadaMedia (6.5)1.9%💥 ExploitOpen Newsletter28/12/200616/6/2026
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php.
ModificadaAlta (7.5)3.4%💥 ExploitKnusperleicht Newsletter5/8/200616/6/2026
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH parameter.
ModificadaAlta (7.5)2.3%💥 ExploitAspburst Mynewsletter7/6/200616/6/2026
Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.
ModificadaMedia (5.1)2.6%💥 ExploitArtmedic Webdesign Artmedic Newsletter26/5/200616/6/2026
artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as…
ModificadaMedia (5.1)1.1%—Artmedic Webdesign Artmedic Newsletter26/5/200616/6/2026
artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (7.5)1.2%—Manic WEB Mwnewsletter11/4/200616/6/2026
Multiple SQL injection vulnerabilities in MWNewsletter 1.0.0b allow remote attackers to execute arbitrary SQL commands via the (1) user_email parameter to (a) unsubscribe.php or (b) subscribe.php; or the (2) user_name parameter to subscribe.php. NOTE: the provenance of this information is unknown; the details are…
ModificadaMedia (6.8)1.6%—Manic WEB Mwnewsletter11/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in subscribe.php in MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web script or HTML via the user_name parameter.
ModificadaAlta (7.5)1.4%—Manic WEB Mwnewsletter11/4/200616/6/2026
SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php.
ModificadaAlta (7.5)1.4%—Sourceworkshop Newsletter30/3/200616/6/2026
SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.
ModificadaAlta (7.5)1.9%—Dsportal Dsnewsletter15/3/200616/6/2026
Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.
ModificadaAlta (7.5)1.3%—Distinct WEB Creations Newsletterez25/5/200516/6/2026
SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
ModificadaAlta (10)4.1%💥 ExploitZaireweb Solutions Newsletter ZWS6/12/200416/6/2026
admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords.
ModificadaAlta (7.5)3.0%💥 ExploitGregory Kokanosky Phpmynewsletter31/12/200216/6/2026
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.
Orbitaley — Vulnerabilidades