Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 6.2% | — | Planet Concept Planetnews | 13/7/2006 | 16/6/2026 | PlaNet Concept planetNews permite a atacantes remotos evitar la autenticació y ejecutar código de su elección medainte una petición directa de news/admin/planetnews.php. | |
| Modificada | Media (5) | 1.4% | — | Bb-news Blueboy | 6/7/2006 | 16/6/2026 | Blueboy 1.0.3 almacena bb_news_config.inc en la raíz de documentos web con un control de acceso insuficiente, lo que permite a atacantes remotos obtener información sensible, incluyendo la configuración de la base de datos. | |
| Modificada | Media (5.1) | 1.3% | — | Vincent Leclercq News | 6/7/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en divers.php en Vincent Leclercq News 5.2 permite a atacantes remotos ejecutar comandos SQL de su elección a través del (1) identificador y (2) parámetros de texto. | |
| Modificada | Media (6.8) | 1.6% | 💥 Exploit | Newsphp | 6/7/2006 | 16/6/2026 | Vulnerabilidad de múltiples secuencias de comandos en sitios cruzados (XSS)en el archivo index.php de NewsPHP 2006 PRO, que permite a los atacantes remotos inyectar una secuencia web arbitrario o código HTML a través de (1) palabras (2) id, (3) cat_id y (4) tim parameters, que no se limpian antes de ser devuelto el… | |
| Modificada | Media (5.8) | 2.0% | 💥 Exploit | Vincent Leclercq News | 6/7/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en divers.php en Vincent Leclercq News v5.2 permite a atacantes remotos inyectar web script o HTML de su elección a través de los parámetros (1) id y (2) disabled. | |
| Modificada | Media (5) | 1.5% | — | Vincent Leclercq News | 6/7/2006 | 16/6/2026 | index.php en Vincent Leclercq News 5.2 permite a los atacantes remotos obtener información sensible, como la ruta de instalación, a través del parámetro mail[] con valores no válidos. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Newsphp | 6/7/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en index.php en NewsPHP 2006 PRO, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) words, (2) id, (3) topmenuitem, y (4) cat_id en (a) index.php; y el parámetro (5) category en (b) inc/rss_feed.php. | |
| Modificada | Media (5.1) | 2.0% | 💥 Exploit | Fusionphp Fusion News | 6/7/2006 | 16/6/2026 | Vulnerabilidad de salto de directorio en sources/post.php en Fusion News v1.0, cuando register_globals está habilitado, permite a atacantes remotos incluir ficheros de su elección a través de una secuencia .. (punto punto)en el parámetro fil_config, lo que puede ser utilizado para ejecutar código PHP que ha sido… | |
| Modificada | Alta (7.5) | 1.3% | — | Carlos Sanchez Valle Mynewsgroups | 3/7/2006 | 16/6/2026 | Una vulnerabilidad de inyección de SQL en tree.php en MyNewsGroups 0.6 permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro grp_id. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Softnews Media Group Datalife Engine | 24/6/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en index.php en DataLife Engine v4.1 y anteriores permite a atacantes remotos ejecutar comandos SQL a través de valores de doble codificación en el parámetro user en una acción userinfo. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Aspburst Mynewsletter | 7/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección SQL en myNewsletter 1.1.2 y anteriores versiones lo que permite a atacantes remotos ejecutar comandos arbitrarios a través del parámetro UserName en (1) validatelogin.asp o (2) adminlogin.asp. | |
| Modificada | Alta (7.5) | 1.3% | — | Alex News-engine | 7/6/2006 | 16/6/2026 | SQL injection vulnerability in newscomments.php in Alex News-Engine 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter. | |
| Modificada | Media (6.4) | 2.9% | 💥 Exploit | PRE Projects PRE News Manager | 2/6/2006 | 16/6/2026 | SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php.… | |
| Modificada | Media (5.8) | 2.8% | — | PRE Projects PRE News Manager | 31/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Pre News Manager 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and… | |
| Modificada | Media (5.1) | 2.3% | — | Dgnews | 31/5/2006 | 16/6/2026 | admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Katy Whitton Newscmslite | 30/5/2006 | 16/6/2026 | newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ". | |
| Modificada | Media (5.1) | 2.6% | 💥 Exploit | Artmedic Webdesign Artmedic Newsletter | 26/5/2006 | 16/6/2026 | artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the logfile parameter in a direct request to log.php, which causes the $logfile variable to be redefined to an attacker-controlled value, as… | |
| Modificada | Media (5.1) | 1.1% | — | Artmedic Webdesign Artmedic Newsletter | 26/5/2006 | 16/6/2026 | artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modify arbitrary files and execute arbitrary PHP code via the email parameter to newsletter_log.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (6.4) | 14% | 💥 Exploit | Florian Amrhein Newsportal | 24/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newsportal (TRanx rebuilded), allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter. | |
| Modificada | Media (5.8) | 1.2% | — | Florian Amrhein Newsportal | 24/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Florian Amrhein NewsPortal before 0.37, and possibly TR Newsportal (TRanx rebuilded), allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Xfairguy Codeavalanche News | 20/5/2006 | 16/6/2026 | SQL injection vulnerability in default.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to execute arbitrary SQL commands via the password field. | |
| Modificada | Media (6.8) | 1.6% | — | Xfairguy Codeavalanche News | 20/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to inject arbitrary web script or HTML via the Headline field. NOTE: if this issue is limited to administrators, and if it is expected behavior for administrators to be able to generate HTML, then this… | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Scoznet Scoznews | 19/5/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[main_path] parameter in (1) functions.php, (2) template.php, (3) news.php, (4) help.php, (5) mail.php, (6) Admin/admin_cats.php, (8) Admin/admin_edit.php, (9)… | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Unclassified Newsboard | 16/5/2006 | 16/6/2026 | Directory traversal vulnerability in unb_lib/abbc.conf.php in Unclassified NewsBoard (UNB) 1.6.1 patch 1 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the ABBC[Config][smileset] parameter to… | |
| Modificada | Baja (2.6) | 2.3% | 💥 Exploit | Unclassified Newsboard | 16/5/2006 | 16/6/2026 | Directory traversal vulnerability in bb_lib/abbc.css.php in Unclassified NewsBoard (UNB) 1.5.3-d and possibly earlier versions, when register_globals is enabled, allows remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing null byte (%00) in the design_path parameter. NOTE: this is… |