Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 1.9% | 💥 Exploit | Simplenews | 11/5/2007 | 16/6/2026 | SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Cutephp Cutenews | 2/3/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: issue might overlap CVE-2004-1660 or… | |
| Modificada | Baja (3.5) | 1.8% | 💥 Exploit | Enthrallweb Enews | 29/12/2006 | 16/6/2026 | myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Cutenews Aj-fork | 14/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter. | |
| Modificada | Media (4.3) | 1.6% | 💥 Exploit | Cutephp Cutenews | 5/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Freenews | 4/11/2006 | 16/6/2026 | Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. (dot dot) sequence in the chemin parameter, when the aff_news parameter is not set to "1." | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Freenews | 10/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Cutephp Cutenews | 29/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter to (1) show_news.php or (2) search.php. NOTE: CVE analysis as of 20060829 has not identified any scenarios in which these vectors could result in remote file… | |
| Modificada | Baja (2.6) | 0.90% | — | Cutephp Cutenews | 18/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Cutephp Cutenews | 9/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters. | |
| Modificada | Media (6.4) | 1.4% | — | Cutephp Cutenews | 9/5/2006 | 16/6/2026 | CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an error message. | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | Corenews | 26/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php. | |
| Modificada | Media (6.4) | 2.2% | — | Corenews | 26/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter. NOTE: this is a different vector than CVE-2006-1212, although it might be the same primary issue. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Cutephp Cutenews | 20/4/2006 | 16/6/2026 | Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist. | |
| Modificada | Media (5.1) | 1.3% | — | R2xdesign Qlitenews | 1/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | |
| Modificada | Media (5) | 1.6% | — | Cutephp Cutenews | 21/3/2006 | 16/6/2026 | Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the archive parameter in an HTTP POST or COOKIE request, which… | |
| Modificada | Media (5) | 1.5% | — | Cutephp Cutenews | 21/3/2006 | 16/6/2026 | CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path. | |
| Modificada | Alta (10) | 3.6% | — | Himpfen Consulting PHP Simplenews | 19/3/2006 | 16/6/2026 | admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Corenews | 14/3/2006 | 16/6/2026 | Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability. NOTE: this vulnerability could not be confirmed by source code inspection of CoreNews 2.0.1, which does not appear to use… | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Cutephp Cutenews | 9/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Cutephp Cutenews | 25/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter. | |
| Modificada | Media (5) | 1.2% | — | Cutephp Cutenews | 16/11/2005 | 16/6/2026 | index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Cutephp Cutenews | 6/11/2005 | 16/6/2026 | Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Cutephp Cutenews | 21/9/2005 | 16/6/2026 | Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php. | |
| Modificada | Media (4.3) | 1.2% | — | Cutephp Cutenews | 21/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php. |