Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.52% | — | Newsbee Project Newsbee | 14/1/2018 | 17/6/2026 | NewsBee allows XSS via the Company Name field in the Settings under admin/admin.php. | |
| Modificada | Crítica (9.8) | 1.7% | — | Newsbee Project Newsbee | 8/1/2018 | 17/6/2026 | SQL injection vulnerability in NewsBee CMS allow remote attackers to execute arbitrary SQL commands. | |
| Modificada | Media (6.1) | 1.4% | — | E-goi Smart Marketing SMS AND Newsletters Forms | 1/1/2018 | 17/6/2026 | The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter. | |
| Modificada | Media (6.1) | 0.64% | — | Stivasoft Phpjabbers Newsletter Script | 30/12/2017 | 17/6/2026 | PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 Exploit | Geniusocean News | 31/10/2017 | 17/6/2026 | Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 Exploit | Geniusocean Newspaper | 31/10/2017 | 17/6/2026 | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | |
| Modificada | Alta (8.8) | 3.1% | — | Newsbeuter | 17/9/2017 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its… | |
| Modificada | Alta (8.8) | 6.4% | — | NewsbeuterDebian Linux | 23/8/2017 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL. | |
| Modificada | Alta (7.5) | 1.2% | — | Google News AND Weather | 19/7/2017 | 17/6/2026 | The Google News and Weather application before 3.3.1 for Android allows remote attackers to read OAuth tokens by sniffing the network and leveraging the lack of SSL. | |
| Modificada | Crítica (9.8) | 48% | — | News System Project News System | 7/4/2017 | 17/6/2026 | SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed. | |
| Modificada | Baja (3.5) | 6.1% | 💥 Exploit | Newstatpress Project Newstatpress | 27/5/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php. | |
| Modificada | Media (6.5) | 9.3% | 💥 Exploit | Newstatpress Project Newstatpress | 27/5/2015 | 17/6/2026 | SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php. | |
| Modificada | Baja (3.5) | 0.95% | — | Taxonews Project Taxonews | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Taxonews module before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a term name in a block. | |
| Modificada | Media (4.3) | 1.2% | — | Nishishi Fumy News Clipper | 1/2/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in hb.cgi in Nishishi Factory Fumy News Clipper 2.x before 2.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Scriptbrasil Taboada Macronews | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Ienvisage Pakistan Cricket News | 21/10/2014 | 17/6/2026 | The Pakistan Cricket News (aka com.conduit.app_cf18df8bdf454eb0a836e2d29886bc40.app) application 1.21.38.6504 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.29% | — | Circa News | 21/10/2014 | 17/6/2026 | The Circa News (aka cir.ca) application 2.1.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Xinhua-news Xinhua International | 21/10/2014 | 17/6/2026 | The Xinhua International (aka org.xinhua.xnews_international) application 5.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | News Revolution - Bahrain Project News Revolution - Bahrain | 21/10/2014 | 17/6/2026 | The news revolution - bahrain (aka com.news.revolution.BH) application 3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Thailand Investor News Project Thailand Investor News | 20/10/2014 | 17/6/2026 | The Thailand Investor News (aka nudecreative.thaistock.set) application 1.39s for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Biebernoticias Bieber News NOW | 20/10/2014 | 17/6/2026 | The Bieber News Now (aka com.jbnews) application 12.0.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Basketball News & Videos Project Basketball News & Videos | 20/10/2014 | 17/6/2026 | The basketball news & videos (aka com.basketbal.news.caesar) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Headlines News India Project Headlines News India | 20/10/2014 | 17/6/2026 | The Headlines news India (aka com.dreamstep.wHEADLINESNEWSINDIA) application 0.21.13219.95110 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Canadapps Central East Lhin News | 20/10/2014 | 17/6/2026 | The Central East LHIN News (aka com.wCentralEastLHINNews) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Echonewshk Echo News | 19/10/2014 | 17/6/2026 | The Echo News (aka com.solo.report) 1.10 application (beta) for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |