Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.7%—Md-systems Simplenews1/11/201316/6/2026
Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an email address.
ModificadaAlta (7.5)1.1%—News Search Project News Search20/7/201316/6/2026
SQL injection vulnerability in the News Search (news_search) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.2%—Georg Ringer News1/7/201316/6/2026
SQL injection vulnerability in the News system (news) extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)1.2%—Lina Wolf SEO Pack FOR TT News27/6/201316/6/2026
SQL injection vulnerability in the SEO Pack for tt_news extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)2.6%💥 ExploitSimpilotgroup POP UP News10/5/201316/6/2026
SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. NOTE: this was originally reported as a problem in phpVMS.
ModificadaMedia (4.3)1.8%—Sourcefabric Newscoop22/2/201316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to application/modules/admin/controllers/LanguagesController.php or (2) user parameter to…
ModificadaMedia (4.3)0.89%—Weathernews Touch6/2/201316/6/2026
The Weathernews Touch application 2.3.2 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.
ModificadaMedia (6)1.1%—Simplenews Scheduler Project Simplenews Scheduler3/12/201216/6/2026
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.
ModificadaMedia (4.3)1.3%—Steve Lockwood Ticketyboo News Ticker17/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (4.3)2.4%💥 ExploitSourcefabric Newscoop27/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the f_user_name parameter.
ModificadaMedia (4.3)2.9%💥 ExploitSourcefabric Newscoop27/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arbitrary web script or HTML via the (1) Back parameter to admin/ad.php, or the (2) token or (3) f_email parameter to admin/password_check_token.php.
ModificadaAlta (7.5)2.5%💥 ExploitSourcefabric Newscoop27/8/201216/6/2026
SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitrary SQL commands via the f_country_code parameter.
ModificadaMedia (6.8)5.6%💥 ExploitSourcefabric Newscoop27/8/201216/6/2026
Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) include/phorum_load.php, (2) conf/install_conf.php, or (3)…
ModificadaAlta (7.5)1.3%💥 ExploitChillcreations MOD Ccnewsletter14/8/201216/6/2026
SQL injection vulnerability in helper/popup.php in the ccNewsletter (mod_ccnewsletter) component 1.0.7 through 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)2.3%—Wpslideshow Image News Slider14/8/201216/6/2026
Unspecified vulnerability in the Image News slider plugin before 3.3 for WordPress has unspecified impact and remote attack vectors.
ModificadaMedia (6.8)1.1%💥 ExploitUtopiasoftware News PRO14/8/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts.
ModificadaMedia (5)1.5%—Joobi COM Jnews13/8/201216/6/2026
The jNews (com_jnews) component 7.5.1 for Joomla! allows remote attackers to obtain sensitive information via the emailsearch parameter, which reveals the installation path in an error message.
ModificadaMedia (5)11%💥 ExploitWordpress Plugin Newsletter Plugin19/6/201216/6/2026
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the data parameter.
ModificadaBaja (2.6)1.8%—Newsgator Feeddemon15/6/201216/6/2026
Cross-site scripting (XSS) vulnerability in FeedDemon before 4.0, when the feed preview option is enabled, allows remote attackers to inject arbitrary web script or HTML via a feed.
ModificadaAlta (7.5)2.1%💥 ExploitInternet-works NUS Newssystem23/11/201116/6/2026
SQL injection vulnerability in Nus.php in NUs Newssystem 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.0%💥 ExploitWanewsletter9/10/201116/6/2026
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.5%—Antisocialmediallc Antisnews28/9/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Antisnews theme before 1.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
ModificadaMedia (4.3)1.5%—Devpress News28/9/201116/6/2026
Cross-site scripting (XSS) vulnerability in the News theme before 0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cpage parameter.
ModificadaMedia (4.3)0.86%💥 ExploitNetwork-13 N-13 News25/1/201116/6/2026
Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information.
ModificadaMedia (5)2.7%💥 ExploitWebwiz WEB WIZ Newspad1/12/201016/6/2026
Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/NewsPad.mdb.