Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.7% | — | Md-systems Simplenews | 1/11/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an email address. | |
| Modificada | Alta (7.5) | 1.1% | — | News Search Project News Search | 20/7/2013 | 16/6/2026 | SQL injection vulnerability in the News Search (news_search) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Georg Ringer News | 1/7/2013 | 16/6/2026 | SQL injection vulnerability in the News system (news) extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Lina Wolf SEO Pack FOR TT News | 27/6/2013 | 16/6/2026 | SQL injection vulnerability in the SEO Pack for tt_news extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Simpilotgroup POP UP News | 10/5/2013 | 16/6/2026 | SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. NOTE: this was originally reported as a problem in phpVMS. | |
| Modificada | Media (4.3) | 1.8% | — | Sourcefabric Newscoop | 22/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to application/modules/admin/controllers/LanguagesController.php or (2) user parameter to… | |
| Modificada | Media (4.3) | 0.89% | — | Weathernews Touch | 6/2/2013 | 16/6/2026 | The Weathernews Touch application 2.3.2 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files. | |
| Modificada | Media (6) | 1.1% | — | Simplenews Scheduler Project Simplenews Scheduler | 3/12/2012 | 16/6/2026 | The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron. | |
| Modificada | Media (4.3) | 1.3% | — | Steve Lockwood Ticketyboo News Ticker | 17/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the f_user_name parameter. | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arbitrary web script or HTML via the (1) Back parameter to admin/ad.php, or the (2) token or (3) f_email parameter to admin/password_check_token.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitrary SQL commands via the f_country_code parameter. | |
| Modificada | Media (6.8) | 5.6% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) include/phorum_load.php, (2) conf/install_conf.php, or (3)… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Chillcreations MOD Ccnewsletter | 14/8/2012 | 16/6/2026 | SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Wpslideshow Image News Slider | 14/8/2012 | 16/6/2026 | Unspecified vulnerability in the Image News slider plugin before 3.3 for WordPress has unspecified impact and remote attack vectors. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Utopiasoftware News PRO | 14/8/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts. | |
| Modificada | Media (5) | 1.5% | — | Joobi COM Jnews | 13/8/2012 | 16/6/2026 | The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Wordpress Plugin Newsletter Plugin | 19/6/2012 | 16/6/2026 | Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter. | |
| Modificada | Baja (2.6) | 1.8% | — | Newsgator Feeddemon | 15/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FeedDemon before 4.0, when the feed preview option is enabled, allows remote attackers to inject arbitrary web script or HTML via a feed. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Internet-works NUS Newssystem | 23/11/2011 | 16/6/2026 | SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Wanewsletter | 9/10/2011 | 16/6/2026 | SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Antisocialmediallc Antisnews | 28/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Antisnews theme before 1.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Devpress News | 28/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the News theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter. | |
| Modificada | Media (4.3) | 0.86% | 💥 Exploit | Network-13 N-13 News | 25/1/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Webwiz WEB WIZ Newspad | 1/12/2010 | 16/6/2026 | Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/NewsPad.mdb. |