Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.55%—Mayurik Best Online News Portal15/5/202517/6/2026
A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /search.php. The manipulation of the argument searchtitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaCrítica (9.3)0.42%—Mayurik Best Online News Portal3/3/202517/6/2026
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php.
AnalizadaCrítica (9.3)0.42%—Mayurik Best Online News Portal3/3/202517/6/2026
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.
AnalizadaCrítica (9.3)0.42%—Mayurik Best Online News Portal3/3/202517/6/2026
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.
AnalizadaCrítica (9.3)0.42%—Mayurik Best Online News Portal3/3/202517/6/2026
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php.
AnalizadaCrítica (9.3)0.42%—Mayurik Best Online News Portal3/3/202517/6/2026
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php.
AnalizadaCrítica (9.3)0.42%—Mayurik Best Online News Portal3/3/202517/6/2026
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php.
AnalizadaCrítica (9.3)0.42%—Mayurik Best Online News Portal3/3/202517/6/2026
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.
AnalizadaMedia (6.9)0.49%—Phpgurukul News Portal3/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul News Portal 4.1. This issue affects some unknown processing of the file /login.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (5.3)0.64%—Mayurik Best Online News Portal19/9/202417/6/2026
A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affects unknown code of the file /news-details.php of the component Comment Section. The manipulation of the argument name leads to sql injection. The attack can be initiated remotely. The exploit has…
ModificadaMedia (5.3)0.56%—Mayurik Best Online News Portal14/6/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.3)0.81%—Phpgurukul News Portal Project15/4/202417/6/2026
A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue affects some unknown processing of the file search.php. The manipulation of the argument searchtitle leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaMedia (5.3)0.77%—Phpgurukul News Portal Project15/4/202417/6/2026
A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the argument posttitle/category leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.81%—Mayurik Best Online News Portal9/4/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack can be…
ModificadaBaja (3.7)0.85%—Mayurik Best Online News Portal12/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be…
ModificadaCrítica (9.8)0.81%—Mayurik Best Online News Portal12/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
ModificadaCrítica (9.8)1.1%—Itechscripts News Portal Script16/7/202217/6/2026
A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function of the file /news-portal-script/information.php. The manipulation of the argument inf leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
ModificadaMedia (5.9)1.8%—Phpgurukul News Portal27/10/202117/6/2026
SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap…
ModificadaMedia (4.8)0.63%—Online News Portal Project Online News Portal26/1/202117/6/2026
Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter.
ModificadaMedia (5)14%💥 ExploitIjoomla COM News Portal8/4/201016/6/2026
Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)2.3%💥 ExploitYanick Bourbeau Lightweight News Portal8/9/200916/6/2026
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4) vote, or (5) modifynews actions.
ModificadaMedia (4.3)1.4%💥 ExploitYanick Bourbeau Lightweight News Portal8/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) photo parameter to show_photo.php, (2) potd parameter to show_potd.php, or (3) the Current question field in a vote action to admin.php.
ModificadaAlta (7.5)0.93%💥 ExploitJoomla COM News PortalJoomla12/6/200816/6/2026
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.
ModificadaMedia (6.4)1.2%—Web4future News Portal9/5/200616/6/2026
Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php.
ModificadaMedia (5.8)1.1%—Web4future News Portal9/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php. NOTE: this issue might be resultant from SQL injection.
Orbitaley — Vulnerabilidades