Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2782▼ 316 respecto a la semana anterior
Críticas / altas1289▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 1.3% | — | Reamday Enterprises Magic News Lite | 16/2/2006 | 16/6/2026 | profile.php en Reamday Enterprises Magic News Lite 1.2.3, cuando "register_globals" está habilitado, permite a atacantes remotos modificar el comportamiento del programa, potencialmente evitando controles de autenticación, mediante la modificación de las variables (1) action, (2) passwd, (3) admin_password, (4)… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Solucija Snews | 15/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field. | |
| Modificada | Alta (7.5) | 1.3% | — | Solucija Snews | 15/2/2006 | 16/6/2026 | SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters. | |
| Modificada | Media (6.4) | 4.7% | 💥 Exploit | Farsinews | 13/2/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Ashwebstudio Ashnews | 2/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ashnews.php in Derek Ashauer ashNews 0.83 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Farsinews | 1/2/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabled, allows remote attackers to include arbitrary files via a URL in the cutepath parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Newsphp | 25/1/2006 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en index.php en NewsPHP permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro (1) "discuss", (2) "tim", (3) "id", (4) "last", y (5) "limit". | |
| Modificada | Media (5) | 1.4% | — | Webmobo Wbnews | 18/1/2006 | 16/6/2026 | Cross-site scripting vulnerability in WBNews 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Name field. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Php-nuke News ModulePhp-nuke Pool Module | 12/1/2006 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Reamday Enterprises Magic News Plus | 10/1/2006 | 16/6/2026 | settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters. | |
| Modificada | Alta (7.5) | 1.5% | — | Webwiz Database LoginWebwiz JournalWebwiz Site NewsWebwiz Weekly Poll | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in check_user.asp in multiple Web Wiz products including (1) Site News 3.06 and earlier, (2) Journal 1.0 and earlier, (3) Polls 3.06 and earlier, and (4) and Database Login 1.71 and earlier allows remote attackers to execute arbitrary SQL commands via the txtUserName parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Direct News | 28/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Direct News 4.9 allow remote attackers to execute arbitrary SQL commands via (1) the setLang parameter in index.php and (2) unspecified search module parameters. | |
| Modificada | Alta (7.5) | 1.8% | — | Utopia Software Utopia News PRO | 14/12/2005 | 16/6/2026 | Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in… | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Sitebeater News SystemAI | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Solupress News | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Solupress News 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 3/12/2005 | 16/6/2026 | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | N-13 News | 1/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in N-13 News 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Dmanews | 1/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in DMANews 0.904 and 0.910 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in a comments action and the (2) sortorder and (3) display_num parameters in a news_list action. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Q-news | 29/11/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in q-news.php in Q-News 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Solucija Snews | 27/11/2005 | 16/6/2026 | SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpwordpress PHP News AND Article Manager | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Fscripts Fantastic News | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Unclassified Newsboard | 19/11/2005 | 16/6/2026 | SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to execute arbitrary SQL commands via the (1) DateFrom or (2) DateUntil parameter to forum.php. | |
| Modificada | Media (5) | 1.2% | — | Cutephp Cutenews | 16/11/2005 | 16/6/2026 | index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Cutephp Cutenews | 6/11/2005 | 16/6/2026 | Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php. |