Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.6)1.7%—Czaries Network Czarnews6/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in news.php in CzarNews 1.14 allows remote attackers to inject arbitrary web script or HTML via the email parameter.
ModificadaMedia (5.1)2.4%—Czaries Network Czarnews6/4/200616/6/2026
Multiple SQL injection vulnerabilities in CzarNews 1.14 allow remote attackers to execute arbitrary SQL commands via the (1) usern or (2) passw parameters to (a) cn_auth.php, (3) s parameter to (b) news.php, or (4) a parameter to (c) dpost.php.
ModificadaMedia (5.1)2.3%—Aweb Labs Awebnews4/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in visview.php in aWebNews 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) yname, (2) emailadd, (3) subject, and (4) comment parameters.
ModificadaMedia (5)1.8%💥 ExploitAweb Labs Awebnews4/4/200616/6/2026
Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.
ModificadaAlta (7.5)1.8%—Vscripts.pl Qlnews2/4/200616/6/2026
Direct static code injection vulnerability in QLnews 1.2 allows remote authenticated administrators to execute arbitrary PHP code by modifying config.php.
ModificadaMedia (6.8)1.5%—Vscripts.pl Qlnews2/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in news.php in QLnews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorx and (2) newsx parameters.
ModificadaMedia (5.1)1.3%—R2xdesign Qlitenews1/4/200616/6/2026
Multiple SQL injection vulnerabilities in loginprocess.php in qliteNews 2005.07.01 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
ModificadaAlta (7.5)1.9%—Skintech Phpnewsmanager31/3/200616/6/2026
Multiple SQL injection vulnerabilities in SkinTech phpNewsManager 1.48 allow remote attackers to execute arbitrary SQL commands via unspecified parameters, possibly (1) id and (2) topicid, in (a) browse.php, (b) category.php, (c) gallery.php, (d) poll.php, and (e) possibly other unspecified scripts. NOTE: portions of…
ModificadaMedia (4.3)1.3%—Vscripts Vnews30/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in news.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) autorkomentarza and (2) tresckomentarza parameters.
ModificadaAlta (7.5)1.8%—Null News30/3/200616/6/2026
Multiple SQL injection vulnerabilities in Null news allow remote attackers to execute arbitrary SQL commands via (1) the user_email parameter in (a) lostpass.php, and the (2) user_email and (3) user_username parameters in (b) sub.php and (c) unsub.php.
ModificadaAlta (7.5)1.4%—Sourceworkshop Newsletter30/3/200616/6/2026
SQL injection vulnerability in newsletter.php in Sourceworkshop newsletter 1.0 allows remote attackers to execute arbitrary SQL commands via the newsletteremail parameter.
ModificadaAlta (7.5)3.5%💥 ExploitVscripts Vnews30/3/200616/6/2026
Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.
ModificadaAlta (9)3.4%—Vscripts Vnews30/3/200616/6/2026
Direct static code injection vulnerability in admin/config.php in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allows remote authenticated administrators to execute code by inserting the code into variables that are stored in admin/config.php.
ModificadaMedia (5)1.6%—Cutephp Cutenews21/3/200616/6/2026
Directory traversal vulnerability in inc/functions.inc.php in CuteNews 1.4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the archive parameter in an HTTP POST or COOKIE request, which…
ModificadaMedia (5)1.5%—Cutephp Cutenews21/3/200616/6/2026
CuteNews 1.4.1 and possibly other versions allows remote attackers to obtain the installation path via unspecified vectors involving an invalid file path.
ModificadaAlta (10)3.6%—Himpfen Consulting PHP Simplenews19/3/200616/6/2026
admin.php in Himpfen Consulting Company PHP SimpleNEWS 1.0.0 allows remote attackers to bypass authentication by setting the admin parameter in a cookie.
ModificadaAlta (7.5)1.3%💥 ExploitOxynews19/3/200616/6/2026
SQL injection vulnerability in index.php in OxyNews allows remote attackers to execute arbitrary SQL commands via the oxynews_comment_id parameter.
ModificadaAlta (7.5)1.9%—Dsportal Dsnewsletter15/3/200616/6/2026
Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.
ModificadaMedia (4.3)2.5%💥 ExploitMikael Software Wmnews14/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.
ModificadaAlta (7.5)4.0%💥 ExploitCorenews14/3/200616/6/2026
Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability. NOTE: this vulnerability could not be confirmed by source code inspection of CoreNews 2.0.1, which does not appear to use…
ModificadaAlta (7.5)2.8%—Fscripts Fantastic News10/3/200616/6/2026
PHP remote file inclusion vulnerability in archive.php in Fantastic News 2.1.2 allows remote attackers to include arbitrary files via the CONFIG[script_path] variable. NOTE: 2.1.4 was also reported to be vulnerable.
ModificadaMedia (6.8)2.2%💥 ExploitCutephp Cutenews9/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.
ModificadaMedia (5)1.3%💥 ExploitFscripts Fantastic News3/3/200616/6/2026
SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846.
ModificadaMedia (4.3)2.0%💥 ExploitCutephp Cutenews25/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter.
ModificadaBaja (2.6)1.6%—Reamday Enterprises Magic News Lite16/2/200616/6/2026
preview.php en Reamday Enterprises Magic News Lite 1.2.3, cuando "register_globals" está habilitado, permite a atacantes remotos incluir ficheros arbitrarios mediante una URL en el parámetro php_script_path, que no es inicializado.
Orbitaley — Vulnerabilidades