Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
250 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.94% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 12/3/2008 | 16/6/2026 | SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earlier allows remote attackers to execute arbitrary SQL commands via the msg_id parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Wordpress ST Newsletter Plugin | 12/2/2008 | 16/6/2026 | SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM NewsletterMambo COM NewsletterMambo | 31/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter. | |
| Modificada | Media (6.8) | 2.8% | 💥 Exploit | Nmnnewsletter | 28/12/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to execute arbitrary PHP code via a URL in the output parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Open Newsletter | 10/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in compose.php in OpenNewsletter 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter. | |
| Modificada | Media (6.8) | 0.95% | 💥 Exploit | Alorys-hebergement KwsphpAlorys-hebergement Newsletter Module | 14/10/2007 | 16/6/2026 | SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsletter parameter. | |
| Modificada | Alta (7.5) | 62% | 💥 Exploit | Wanewsletter | 1/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the waroot parameter. | |
| Modificada | Alta (10) | 8.0% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 30/4/2007 | 16/6/2026 | admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action. | |
| Modificada | Alta (10) | 8.2% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 30/4/2007 | 16/6/2026 | admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Active WEB Softwares Active Newsletter | 27/3/2007 | 16/6/2026 | SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execute arbitrary SQL commands via the NewsPaperID parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mxmania Newsletter MX | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Open Newsletter | 28/12/2006 | 16/6/2026 | The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, or execute arbitrary code in conjunction with another vulnerability. | |
| Modificada | Media (6.5) | 1.9% | 💥 Exploit | Open Newsletter | 28/12/2006 | 16/6/2026 | Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting the code into the email parameter to (1) subscribe.php or (2) unsubscribe.php. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Knusperleicht Newsletter | 5/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Aspburst Mynewsletter | 7/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp. | |
| Modificada | Media (5.1) | 2.6% | 💥 Exploit | Artmedic Webdesign Artmedic Newsletter | 26/5/2006 | 16/6/2026 | artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as… | |
| Modificada | Media (5.1) | 1.1% | — | Artmedic Webdesign Artmedic Newsletter | 26/5/2006 | 16/6/2026 | artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (7.5) | 1.2% | — | Manic WEB Mwnewsletter | 11/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MWNewsletter 1.0.0b allow remote attackers to execute arbitrary SQL commands via the (1) user_email parameter to (a) unsubscribe.php or (b) subscribe.php; or the (2) user_name parameter to subscribe.php. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (6.8) | 1.6% | — | Manic WEB Mwnewsletter | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in subscribe.php in MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web script or HTML via the user_name parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Manic WEB Mwnewsletter | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Sourceworkshop Newsletter | 30/3/2006 | 16/6/2026 | SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Dsportal Dsnewsletter | 15/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Distinct WEB Creations Newsletterez | 25/5/2005 | 16/6/2026 | SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Zaireweb Solutions Newsletter ZWS | 6/12/2004 | 16/6/2026 | admin.php in Newsletter ZWS allows remote attackers to gain administrative privileges via a list_user operation with the ulevel parameter set to 1 (administrator level), which lists all users and their passwords. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter. |