Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.52%—Newsbee Project Newsbee14/1/201817/6/2026
NewsBee allows XSS via the Company Name field in the Settings under admin/admin.php.
ModificadaCrítica (9.8)1.7%—Newsbee Project Newsbee8/1/201817/6/2026
SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands.
ModificadaMedia (6.1)1.4%—E-goi Smart Marketing SMS AND Newsletters Forms1/1/201817/6/2026
The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
ModificadaMedia (6.1)0.64%—Stivasoft Phpjabbers Newsletter Script30/12/201717/6/2026
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
ModificadaCrítica (9.8)2.6%💥 ExploitGeniusocean News31/10/201717/6/2026
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
ModificadaCrítica (9.8)2.6%💥 ExploitGeniusocean Newspaper31/10/201717/6/2026
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
ModificadaAlta (8.8)3.1%—Newsbeuter17/9/201717/6/2026
Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its…
ModificadaAlta (8.8)6.4%—NewsbeuterDebian Linux23/8/201717/6/2026
Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.
ModificadaAlta (7.5)1.2%—Google News AND Weather19/7/201717/6/2026
The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL.
ModificadaCrítica (9.8)48%—News System Project News System7/4/201717/6/2026
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
ModificadaBaja (3.5)6.1%💥 ExploitNewstatpress Project Newstatpress27/5/201517/6/2026
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.
ModificadaMedia (6.5)9.3%💥 ExploitNewstatpress Project Newstatpress27/5/201517/6/2026
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.
ModificadaBaja (3.5)0.95%—Taxonews Project Taxonews21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Taxonews module before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a term name in a block.
ModificadaMedia (4.3)1.2%—Nishishi Fumy News Clipper1/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in hb.cgi in Nishishi Factory Fumy News Clipper 2.x before 2.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.5)1.1%💥 ExploitScriptbrasil Taboada Macronews13/1/201517/6/2026
SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5.4)0.27%—Ienvisage Pakistan Cricket News21/10/201417/6/2026
The Pakistan Cricket News (aka com.conduit.app_cf18df8bdf454eb0a836e2d29886bc40.app) application 1.21.38.6504 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.29%—Circa News21/10/201417/6/2026
The Circa News (aka cir.ca) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Xinhua-news Xinhua International21/10/201417/6/2026
The Xinhua International (aka org.xinhua.xnews_international) application 5.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—News Revolution - Bahrain Project News Revolution - Bahrain21/10/201417/6/2026
The news revolution - bahrain (aka com.news.revolution.BH) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Thailand Investor News Project Thailand Investor News20/10/201417/6/2026
The Thailand Investor News (aka nudecreative.thaistock.set) application 1.39s for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Biebernoticias Bieber News NOW20/10/201417/6/2026
The Bieber News Now (aka com.jbnews) application 12.0.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Basketball News & Videos Project Basketball News & Videos20/10/201417/6/2026
The basketball news & videos (aka com.basketbal.news.caesar) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Headlines News India Project Headlines News India20/10/201417/6/2026
The Headlines news India (aka com.dreamstep.wHEADLINESNEWSINDIA) application 0.21.13219.95110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Canadapps Central East Lhin News20/10/201417/6/2026
The Central East LHIN News (aka com.wCentralEastLHINNews) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Echonewshk Echo News19/10/201417/6/2026
The Echo News (aka com.solo.report) 1.10 application (beta) for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades