Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)1.9%💥 ExploitSimplenews11/5/200716/6/2026
SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL commands via the news_id parameter.
ModificadaAlta (7.5)1.2%—Cutephp Cutenews2/3/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in CutePHP CuteNews 1.3.6 allow remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: issue might overlap CVE-2004-1660 or…
ModificadaBaja (3.5)1.8%💥 ExploitEnthrallweb Enews29/12/200616/6/2026
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which allows remote authenticated users to modify certain profile fields of another account by specifying that account's username in a modified MM_recordId parameter.
ModificadaAlta (7.5)2.9%💥 ExploitCutenews Aj-fork14/12/200616/6/2026
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter.
ModificadaMedia (4.3)1.6%💥 ExploitCutephp Cutenews5/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the result parameter.
ModificadaMedia (5)2.9%💥 ExploitFreenews4/11/200616/6/2026
Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. (dot dot) sequence in the chemin parameter, when the aff_news parameter is not set to "1."
ModificadaAlta (7.5)2.8%💥 ExploitFreenews10/10/200616/6/2026
PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.
ModificadaAlta (7.5)1.8%—Cutephp Cutenews29/8/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in CuteNews 1.3.x allow remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter to (1) show_news.php or (2) search.php. NOTE: CVE analysis as of 20060829 has not identified any scenarios in which these vectors could result in remote file…
ModificadaBaja (2.6)0.90%—Cutephp Cutenews18/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in Index.PHP in CuteNews 1.4.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (4.3)2.1%💥 ExploitCutephp Cutenews9/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.
ModificadaMedia (6.4)1.4%—Cutephp Cutenews9/5/200616/6/2026
CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an error message.
ModificadaMedia (6.4)1.2%💥 ExploitCorenews26/4/200616/6/2026
Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.
ModificadaMedia (6.4)2.2%—Corenews26/4/200616/6/2026
PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter. NOTE: this is a different vector than CVE-2006-1212, although it might be the same primary issue.
ModificadaMedia (4.3)1.8%💥 ExploitCutephp Cutenews20/4/200616/6/2026
Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist.
ModificadaMedia (5.1)1.3%—R2xdesign Qlitenews1/4/200616/6/2026
Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
ModificadaMedia (5)1.6%—Cutephp Cutenews21/3/200616/6/2026
Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the archive parameter in an HTTP POST or COOKIE request, which…
ModificadaMedia (5)1.5%—Cutephp Cutenews21/3/200616/6/2026
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
ModificadaAlta (10)3.6%—Himpfen Consulting PHP Simplenews19/3/200616/6/2026
admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie.
ModificadaAlta (7.5)4.0%💥 ExploitCorenews14/3/200616/6/2026
Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability. NOTE: this vulnerability could not be confirmed by source code inspection of CoreNews 2.0.1, which does not appear to use…
ModificadaMedia (6.8)2.2%💥 ExploitCutephp Cutenews9/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.
ModificadaMedia (4.3)2.0%💥 ExploitCutephp Cutenews25/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter.
ModificadaMedia (5)1.2%—Cutephp Cutenews16/11/200516/6/2026
index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.
ModificadaMedia (5)12%💥 ExploitCutephp Cutenews6/11/200516/6/2026
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.
ModificadaAlta (7.5)6.3%💥 ExploitCutephp Cutenews21/9/200516/6/2026
Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.
ModificadaMedia (4.3)1.2%—Cutephp Cutenews21/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php.
Orbitaley — Vulnerabilidades