Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2782▼ 316 respecto a la semana anterior
Críticas / altas1289▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.6)1.3%—Reamday Enterprises Magic News Lite16/2/200616/6/2026
profile.php en Reamday Enterprises Magic News Lite 1.2.3, cuando "register_globals" está habilitado, permite a atacantes remotos modificar el comportamiento del programa, potencialmente evitando controles de autenticación, mediante la modificación de las variables (1) action, (2) passwd, (3) admin_password, (4)…
ModificadaMedia (4.3)1.8%💥 ExploitSolucija Snews15/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
ModificadaAlta (7.5)1.3%—Solucija Snews15/2/200616/6/2026
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
ModificadaMedia (6.4)4.7%💥 ExploitFarsinews13/2/200616/6/2026
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.
ModificadaMedia (4.3)4.0%💥 ExploitAshwebstudio Ashnews2/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)4.3%💥 ExploitFarsinews1/2/200616/6/2026
PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to include arbitrary files via a URL in the cutepath parameter.
ModificadaAlta (7.5)1.3%💥 ExploitNewsphp25/1/200616/6/2026
Múltiples vulnerabilidades de inyección de SQL en index.php en NewsPHP permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro (1) "discuss", (2) "tim", (3) "id", (4) "last", y (5) "limit".
ModificadaMedia (5)1.4%—Webmobo Wbnews18/1/200616/6/2026
Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field.
ModificadaMedia (5)2.3%💥 ExploitPhp-nuke News ModulePhp-nuke Pool Module12/1/200616/6/2026
Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.
ModificadaMedia (5)2.3%💥 ExploitReamday Enterprises Magic News Plus10/1/200616/6/2026
settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.
ModificadaAlta (7.5)1.5%—Webwiz Database LoginWebwiz JournalWebwiz Site NewsWebwiz Weekly Poll31/12/200516/6/2026
SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter.
ModificadaAlta (7.5)1.2%💥 ExploitDirect News28/12/200516/6/2026
Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters.
ModificadaAlta (7.5)1.8%—Utopia Software Utopia News PRO14/12/200516/6/2026
Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in…
ModificadaMedia (4.3)1.9%💥 ExploitSitebeater News SystemAI5/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter.
ModificadaMedia (4.3)1.9%💥 ExploitSolupress News5/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in search.asp in Solupress News 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.
ModificadaAlta (7.5)1.2%—Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+73/12/200516/6/2026
SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote…
ModificadaAlta (7.5)1.3%💥 ExploitN-13 News1/12/200516/6/2026
SQL injection vulnerability in index.php in N-13 News 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)1.2%💥 ExploitDmanews1/12/200516/6/2026
Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action.
ModificadaAlta (7.5)3.4%💥 ExploitQ-news29/11/200516/6/2026
PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter.
ModificadaAlta (7.5)1.1%💥 ExploitSolucija Snews27/11/200516/6/2026
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.
ModificadaAlta (7.5)1.2%💥 ExploitPhpwordpress PHP News AND Article Manager26/11/200516/6/2026
SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.
ModificadaAlta (7.5)1.3%💥 ExploitFscripts Fantastic News26/11/200516/6/2026
SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaAlta (7.5)1.3%💥 ExploitUnclassified Newsboard19/11/200516/6/2026
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php.
ModificadaMedia (5)1.2%—Cutephp Cutenews16/11/200516/6/2026
index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.
ModificadaMedia (5)12%💥 ExploitCutephp Cutenews6/11/200516/6/2026
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.