Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 1.8% | — | Newsgator Feeddemon | 15/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FeedDemon before 4.0, when the feed preview option is enabled, allows remote attackers to inject arbitrary web script or HTML via a feed. | |
| Modificada | Media (5) | 2.7% | — | Mark Pilgrim Feedparser | 21/5/2012 | 16/6/2026 | Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Scriptsfeed Recipes Listing Portal | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.9% | — | Pleer Wp-twitter-feed | 24/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in magpie_debug.php in the Twitter Feed plugin (wp-twitter-feed) 0.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (4.3) | 2.3% | — | Mark Pilgrim Feedparser | 11/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a javascript: URI. | |
| Modificada | Media (4.3) | 2.5% | — | Mark Pilgrim Feedparser | 11/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via malformed XML comments. | |
| Modificada | Media (5) | 3.3% | — | Mark Pilgrim Feedparser | 11/4/2011 | 16/6/2026 | feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0.1 allows remote attackers to cause a denial of service (application crash) via a malformed DOCTYPE declaration. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Mark Pilgrim Feedparser | 11/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas. | |
| Modificada | Media (4.3) | 4.7% | 💥 Exploit | Pleer RSS Feed Reader | 2/2/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Finalcut Feedlist | 30/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in feedlist/handler_image.php in the FeedList plugin 2.61.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Brotherscripts Scripts DirectoryScriptsfeed Scripts Directory | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-2905. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Brotherscripts Scripts DirectoryScriptsfeed Scripts Directory | 28/7/2010 | 16/6/2026 | SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 11% | 💥 Exploit | Affiliatefeeds COM Datafeeds | 19/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM Newsfeeds | 6/5/2010 | 16/6/2026 | SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php. | |
| Modificada | Media (6.8) | 8.2% | 💥 Exploit | Ternaria COM Jfeedback | 19/4/2010 | 16/6/2026 | Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Scriptsfeed Dating Software | 24/3/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in searchmatch.php in ScriptsFeed Dating Software allow remote attackers to execute arbitrary SQL commands via the (1) txtgender and (2) txtlookgender parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Scriptsfeed Business Directory Software | 24/3/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to execute arbitrary SQL commands via the (1) us and (2) ps parameters. | |
| Modificada | Media (4.3) | 1.3% | — | Alex Barth Feed Element Mapper | 1/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Feed Element Mapper module 5.x before 5.x-1.3, 6.x before 6.x-1.3, and 6.x-2.0-alpha before 6.x-2.0-alpha4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Jce-tech Affiliate Master Datafeed Parser | 15/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Jce-tech Searchfeed Script | 15/9/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |
| Modificada | Media (6.5) | 4.0% | 💥 Exploit | Scriptsfeed Auto Classifieds | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/. | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Scriptsfeed Recipes Listing Portal | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/. | |
| Modificada | Media (6.5) | 3.9% | 💥 Exploit | Scriptsfeed Realtor Classifieds System | 12/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Xigla Absolute News Feed | 14/7/2009 | 16/6/2026 | Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Ijoomla COM Rssfeeder | 17/6/2009 | 16/6/2026 | SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php. |