Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.55% | — | Mayurik Best Online News Portal | 15/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /search.php. The manipulation of the argument searchtitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php. | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php. | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php. | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php. | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php. | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php. | |
| Analizada | Crítica (9.3) | 0.42% | — | Mayurik Best Online News Portal | 3/3/2025 | 17/6/2026 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php. | |
| Analizada | Media (6.9) | 0.49% | — | Phpgurukul News Portal | 3/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file /login.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.64% | — | Mayurik Best Online News Portal | 19/9/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affects unknown code of the file /news-details.php of the component Comment Section. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Modificada | Media (5.3) | 0.56% | — | Mayurik Best Online News Portal | 14/6/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.3) | 0.81% | — | Phpgurukul News Portal Project | 15/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue affects some unknown processing of the file search.php. The manipulation of the argument searchtitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.77% | — | Phpgurukul News Portal Project | 15/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.81% | — | Mayurik Best Online News Portal | 9/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack can be… | |
| Modificada | Baja (3.7) | 0.85% | — | Mayurik Best Online News Portal | 12/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be… | |
| Modificada | Crítica (9.8) | 0.81% | — | Mayurik Best Online News Portal | 12/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 1.1% | — | Itechscripts News Portal Script | 16/7/2022 | 17/6/2026 | A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function of the file /news-portal-script/information.php. The manipulation of the argument inf leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.9) | 1.8% | — | Phpgurukul News Portal | 27/10/2021 | 17/6/2026 | SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap… | |
| Modificada | Media (4.8) | 0.63% | — | Online News Portal Project Online News Portal | 26/1/2021 | 17/6/2026 | Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter. | |
| Modificada | Media (5) | 14% | 💥 Exploit | Ijoomla COM News Portal | 8/4/2010 | 16/6/2026 | Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Yanick Bourbeau Lightweight News Portal | 8/9/2009 | 16/6/2026 | Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4) vote, or (5) modifynews actions. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Yanick Bourbeau Lightweight News Portal | 8/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) photo parameter to show_photo.php, (2) potd parameter to show_potd.php, or (3) the Current question field in a vote action to admin.php. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Joomla COM News PortalJoomla | 12/6/2008 | 16/6/2026 | SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php. | |
| Modificada | Media (6.4) | 1.2% | — | Web4future News Portal | 9/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php. | |
| Modificada | Media (5.8) | 1.1% | — | Web4future News Portal | 9/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php. NOTE: this issue might be resultant from SQL injection. |