Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 1.4% | — | Cutephp Cutenews | 9/5/2006 | 16/6/2026 | CuteNews 1.4.1 allows remote attackers to obtain sensitive information via a direct request to (1) /inc/show.inc.php or (2) /inc/functions.inc.php, which reveal the path in an error message. | |
| Modificada | Media (6.4) | 1.2% | — | Web4future News Portal | 9/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Web4Future News Portal allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) comentarii.php or (2) view.php. | |
| Modificada | Media (5.8) | 1.1% | — | Web4future News Portal | 9/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Web4Future News Portal allow remote attackers to inject arbitrary web script or HTML via the ID parameter to (1) comentarii.php or (2) view.php. NOTE: this issue might be resultant from SQL injection. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Cutephp Cutenews | 9/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters. | |
| Modificada | Alta (7.5) | 1.3% | — | Tuomas Airaksinen Newsadmin | 9/5/2006 | 16/6/2026 | SQL injection vulnerability in readarticle.php in Newsadmin 1.1 allows remote attackers to execute arbitrary SQL commands via the nid parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Planetluc Mynews | 5/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters. | |
| Modificada | Media (6.4) | 1.6% | — | Wilsonncareabusinesses PHP Newsfeed | 2/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Newsfeed 20040723 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to (a) deltables.php, (2) select, (3) header, (4) url, (5) source, or (6) time parameters to (b) manualsubmit.php, (7) num parameter to (c) delete.php, or (8) tablename… | |
| Modificada | Alta (7.5) | 1.2% | — | Ruperts News | 2/5/2006 | 16/6/2026 | SQL injection vulnerability in login.php in Ruperts News allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Aznews | 2/5/2006 | 16/6/2026 | SQL injection vulnerability in news.php in AZNEWS allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Farsinews | 29/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in FarsiNews 2.5.3 Pro and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameters in (a) index.php, and the (3) mod parameter in (b) admin.php. | |
| Modificada | Media (6.4) | 2.2% | — | Corenews | 26/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Core CoreNews 2.0.1 and earlier allows remote authenticated users to execute arbitrary commands via the show parameter. NOTE: this is a different vector than CVE-2006-1212, although it might be the same primary issue. | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | Corenews | 26/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php. | |
| Modificada | Media (5.8) | 2.0% | — | Kcscripts News PublisherKcscripts Portal Pack | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in news/NsVisitor.cgi in KCScripts News Publisher, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Cutephp Cutenews | 20/4/2006 | 16/6/2026 | Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Clanscripte.net Fuju News | 19/4/2006 | 16/6/2026 | edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Clanscripte.net Fuju News | 19/4/2006 | 16/6/2026 | SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Media (5.8) | 2.2% | 💥 Exploit | Farsinews | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter. | |
| Modificada | Baja (2.6) | 1.2% | — | THE WAR Forge Warforge.news | 18/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly including the (1) first_name and (2) last_name parameter in myaccounts.php. NOTE: portions of these details were obtained from third party sources… | |
| Modificada | Media (6.4) | 1.6% | — | Farsinews | 18/4/2006 | 16/6/2026 | Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message. | |
| Modificada | Baja (2.6) | 1.2% | — | THE WAR Forge Warforge.news | 18/4/2006 | 16/6/2026 | SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie. | |
| Modificada | Alta (7.5) | 1.9% | — | Matthew Dingley MD News | 13/4/2006 | 16/6/2026 | MD News 1 allows remote attackers to bypass authentication via a direct request to a script in the Administration Area. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Matthew Dingley MD News | 13/4/2006 | 16/6/2026 | SQL injection vulnerability in admin.php in MD News 1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Manic WEB Mwnewsletter | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in subscribe.php in MWNewsletter 1.0.0b allows remote attackers to inject arbitrary web script or HTML via the user_name parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Manic WEB Mwnewsletter | 11/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MWNewsletter 1.0.0b allow remote attackers to execute arbitrary SQL commands via the (1) user_email parameter to (a) unsubscribe.php or (b) subscribe.php; or the (2) user_name parameter to subscribe.php. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Alta (7.5) | 1.4% | — | Manic WEB Mwnewsletter | 11/4/2006 | 16/6/2026 | SQL injection vulnerability in MWNewsletter 1.0.0b allows remote attackers to execute arbitrary SQL commands via the user_name parameter to unsubscribe.php. |