Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 1.0% | — | Ivanjaros Feed Block | 20/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items." | |
| Modificada | Media (4.3) | 1.0% | — | Drupal Feedapi Mapper | 6/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Feed element mapper 5.x before 5.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the content title in admin/content/node-type/nodetype/map. | |
| Modificada | Alta (7.5) | 1.8% | — | Network-publishing RDF Newsfeed Export | 3/4/2009 | 16/6/2026 | SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Zfeeder | 4/3/2009 | 16/6/2026 | zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Insun Podcast Feedcms | 2/3/2009 | 16/6/2026 | Directory traversal vulnerability in index.php in InSun Feed CMS 1.7.3 19Beta allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the lang parameter. | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Newsgator Feeddemon | 12/2/2009 | 16/6/2026 | Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text attribute in an outline element in a .opml file. | |
| Modificada | Alta (7.5) | 45% | 💥 Exploit | Recly Interactive Feederator | 31/12/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the Recly Interactive Feederator (com_feederator) component 1.0.5 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the (1) mosConfig_absolute_path parameter to (a) add_tmsp.php, (b) edit_tmsp.php and (c) tmsp.php in includes/tmsp/; and… | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Datafeedfile DFF Framework API | 9/10/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a URL in the DFF_config[dir_include] parameter to (1) DFF_affiliate_client_API.php, (2) DFF_featured_prdt.func.php, (3) DFF_mer.func.php, (4) DFF_mer_prdt.func.php, (5)… | |
| Modificada | Alta (10) | 3.6% | 💥 Exploit | Martinwood Datafeed Studio | 3/10/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary PHP code via a URL in the INSTALL_FOLDER parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Datafeed Studio | 3/10/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Datafeed Studio 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Cmsnx Feedback AND Rating Script | 16/5/2008 | 16/6/2026 | SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary SQL commands via the listingid parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Feed2js | 23/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Feed to JavaScript (Feed2JS) 1.91 allows remote attackers to inject arbitrary web script or HTML via a URL in a feed. | |
| Modificada | Media (6.4) | 4.9% | 💥 Exploit | Feedburner Feedsmith | 5/10/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and hijack blog feeds via a request to wp-admin/options-general.php that submits parameter values to FeedBurner_FeedSmith_Plugin.php, as demonstrated by the (1) feedburner_url… | |
| Modificada | Media (4.3) | 2.2% | — | I-systems Inc. Feedreader | 1/10/2007 | 16/6/2026 | Cross-zone scripting vulnerability in the internal browser in i-Systems Feedreader 3.10 allows remote attackers to inject arbitrary web script or HTML via an item in a feed, as demonstrated by a WordPress blog update. NOTE: this was originally reported as XSS. | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Wp-feedstats Wordpress Plugin | 31/7/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, one of which involves an rss2 feed with an invalid or missing blog with an XSS sequence in the query string. | |
| Modificada | Media (6.8) | 68% | 💥 Exploit | Linksnet Newsfeed | 16/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dirpath_linksnet_newsfeed parameter. | |
| Modificada | Media (6.8) | 7.4% | 💥 Exploit | Zebrafeeds | 21/2/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ZebraFeeds 1.0, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the zf_path parameter to (1) aggregator.php and (2) controller.php in newsfeeds/includes/. | |
| Modificada | Media (4.3) | 1.7% | — | Newsgator Feeddemon | 12/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader test suite. | |
| Modificada | Alta (7.5) | 1.5% | — | Chxo Feedsplitter | 6/9/2006 | 16/6/2026 | Eval injection vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to execute arbitrary PHP code via (1) the file specified as the value of the format parameter, and possibly (2) the RSS feed. | |
| Modificada | Media (6.8) | 1.3% | — | Chxo Feedsplitter | 6/9/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to inject arbitrary web script or HTML via the RSS feed. | |
| Modificada | Media (5) | 1.4% | — | Chxo Feedsplitter | 6/9/2006 | 16/6/2026 | CHXO Feedsplitter 2006-01-21 allows remote attackers to read the source code of feedsplitter.php via the showsource function. NOTE: this issue is not a vulnerability in standard distributions, but could be an issue if the source has been modified. | |
| Modificada | Media (5) | 1.7% | — | Chxo Feedsplitter | 6/9/2006 | 16/6/2026 | Directory traversal vulnerability in CHXO Feedsplitter 2006-01-21 allows remote attackers to read arbitrary XML files via .. (dot dot) sequences in the format parameter with a leading ".", which bypasses a security check. | |
| Modificada | Media (6.4) | 1.6% | — | Wilsonncareabusinesses PHP Newsfeed | 2/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) url, (5) source, or (6) time parameters to (b) manualsubmit.php, (7) num parameter to (c) delete.php, or (8) tablename… | |
| Modificada | Media (4.3) | 1.4% | — | Wwwsearchsolutions Searchfeed Search Engine | 29/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SearchFeed Search Engine 1.3.2 and earlier allows remote attackers to inject arbitrary HTML and web script, possibly via the REQ parameter, which is used when performing a search. | |
| Modificada | Media (5) | 1.1% | — | Thesitewizard.com Chfeedback.pl Feedback Form Perl Script | 8/9/2005 | 16/6/2026 | CRLF injection vulnerability in thesitewizard.com chfeedback.pl Feedback Form Perl Script 2.0.1 allows remote attackers to use the script as a mail relay (spam proxy) via CRLF sequences in the (1) name or (2) email fields, which are injected into mail headers. |