Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

401 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.6)1.8%—Newsgator Feeddemon15/6/201216/6/2026
Cross-site scripting (XSS) vulnerability in FeedDemon before 4.0, when the feed preview option is enabled, allows remote attackers to inject arbitrary web script or HTML via a feed.
ModificadaMedia (5)2.7%—Mark Pilgrim Feedparser21/5/201216/6/2026
Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document.
ModificadaAlta (7.5)1.0%💥 ExploitScriptsfeed Recipes Listing Portal2/11/201116/6/2026
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.9%—Pleer Wp-twitter-feed24/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in magpie_debug.php in the Twitter Feed plugin (wp-twitter-feed) 0.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
ModificadaMedia (4.3)2.3%—Mark Pilgrim Feedparser11/4/201116/6/2026
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a javascript: URI.
ModificadaMedia (4.3)2.5%—Mark Pilgrim Feedparser11/4/201116/6/2026
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via malformed XML comments.
ModificadaMedia (5)3.3%—Mark Pilgrim Feedparser11/4/201116/6/2026
feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0.1 allows remote attackers to cause a denial of service (application crash) via a malformed DOCTYPE declaration.
ModificadaMedia (4.3)4.5%💥 ExploitMark Pilgrim Feedparser11/4/201116/6/2026
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas.
ModificadaMedia (4.3)4.7%💥 ExploitPleer RSS Feed Reader2/2/201116/6/2026
Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.
ModificadaMedia (4.3)1.9%—Finalcut Feedlist30/12/201016/6/2026
Cross-site scripting (XSS) vulnerability in feedlist/handler_image.php in the FeedList plugin 2.61.01 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.
ModificadaAlta (7.5)0.96%💥 ExploitBrotherscripts Scripts DirectoryScriptsfeed Scripts Directory28/7/201016/6/2026
SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-2905.
ModificadaAlta (7.5)0.97%💥 ExploitBrotherscripts Scripts DirectoryScriptsfeed Scripts Directory28/7/201016/6/2026
SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)11%💥 ExploitAffiliatefeeds COM Datafeeds19/5/201016/6/2026
Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM Newsfeeds6/5/201016/6/2026
SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php.
ModificadaMedia (6.8)8.2%💥 ExploitTernaria COM Jfeedback19/4/201016/6/2026
Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)1.1%—Scriptsfeed Dating Software24/3/201016/6/2026
Multiple SQL injection vulnerabilities in searchmatch.php in ScriptsFeed Dating Software allow remote attackers to execute arbitrary SQL commands via the (1) txtgender and (2) txtlookgender parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.1%💥 ExploitScriptsfeed Business Directory Software24/3/201016/6/2026
Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to execute arbitrary SQL commands via the (1) us and (2) ps parameters.
ModificadaMedia (4.3)1.3%—Alex Barth Feed Element Mapper1/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in Feed Element Mapper module 5.x before 5.x-1.3, 6.x before 6.x-1.3, and 6.x-2.0-alpha before 6.x-2.0-alpha4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)1.1%—Jce-tech Affiliate Master Datafeed Parser15/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaMedia (4.3)1.5%💥 ExploitJce-tech Searchfeed Script15/9/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script or HTML via the search parameter.
ModificadaMedia (6.5)4.0%💥 ExploitScriptsfeed Auto Classifieds12/8/200916/6/2026
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/.
ModificadaMedia (6.5)3.9%💥 ExploitScriptsfeed Recipes Listing Portal12/8/200916/6/2026
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.
ModificadaMedia (6.5)3.9%💥 ExploitScriptsfeed Realtor Classifieds System12/8/200916/6/2026
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.
ModificadaAlta (7.5)2.5%💥 ExploitXigla Absolute News Feed14/7/200916/6/2026
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.
ModificadaAlta (7.5)0.99%💥 ExploitIjoomla COM Rssfeeder17/6/200916/6/2026
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php.