Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2786▼ 305 respecto a la semana anterior
Críticas / altas1290▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%💥 ExploitNews2net2/11/200516/6/2026
SQL injection vulnerability in index.php in News2Net 3.0.0.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaCrítica (9.8)2.3%—Archilles Newsworld2/11/200516/6/2026
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument.
ModificadaAlta (7.5)1.5%—Archilles Newsworld2/11/200516/6/2026
Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd and (2) session.nwd under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames, hashed passwords, and session IDs, and gain privileges.
ModificadaMedia (4.3)2.6%💥 ExploitUtopia Software Utopia News PRO14/10/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.
ModificadaAlta (7.5)1.8%💥 ExploitUtopiasoftware News PROAI14/10/200516/6/2026
SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.
ModificadaMedia (4.3)1.2%—Cutephp Cutenews21/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php.
ModificadaAlta (7.5)6.3%💥 ExploitCutephp Cutenews21/9/200516/6/2026
Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.
ModificadaMedia (5)1.2%—Stylemotion WEB News14/9/200516/6/2026
WEB//NEWS 1.4 allows remote attackers to obtain sensitive information via a direct request to files in the actions directory, which reveal the path in an error message, as demonstrated using cat.add.php.
ModificadaAlta (7.5)1.2%💥 ExploitStylemotion WEB News14/9/200516/6/2026
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
ModificadaMedia (4.3)2.0%💥 ExploitUnclassified Newsboard8/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field.
ModificadaAlta (7.5)1.2%💥 ExploitPhpfreenews23/8/200516/6/2026
Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php.
ModificadaMedia (4.3)1.8%💥 ExploitPhpfreenews23/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchResults.php.
ModificadaMedia (5)1.2%—Acnews23/8/200516/6/2026
ACNews stores the database in a file under the web document root with a db.inc extension and insufficient access control, which allows remote attackers to obtain sensitive information such as the full pathname of the server.
ModificadaMedia (4.3)1.8%💥 ExploitWEB Content Management News System7/8/200516/6/2026
Vulnerabilidad de scritps en sitios cruzados (XSS) en Web Content Management News System permite a atacantes remotos inyectar script web arbitrario o HTML mediante el parámetro strRootpath de validsession.php o el parámetro strTable de Admin/News/List.php
ModificadaAlta (7.5)1.9%—WEB Content Management News System7/8/200516/6/2026
Web Content Management News System permite a atacantes remotos crear cuentas de su elección y ganar privilegios mediante una petición directa a Admin/Users/AddModifyInput.php.
ModificadaAlta (7.5)1.5%—Silver-scripts Silvernews5/8/200516/6/2026
Vulnerabilidad de inyección de SQL en SilverNews 2.0.3 permite que atacantes remotos ejecuten comandos SQL en el campo "user" de la página de login del panel de control de administración.
ModificadaMedia (4.3)0.99%—Cutephp Cutenews27/7/200516/6/2026
Vulnerabilidad de secuencia de comandos en sitios cruzados en CuteNews 1.3.6 permite que atacantes remotos inyecten script web arbitrario o HTML mediante 1) el parámetro "lastusername" en index.php o 2) el parámetro "selected_search_arch" en search.php.
ModificadaMedia (5)1.3%—Cutephp Cutenews27/7/200516/6/2026
show_news.php en CuteNews 1.3.6 permite que atacantes remotos obtengan el path absoluto al servidor mediante un parámetro "archive" inválido.
ModificadaAlta (7.5)1.2%💥 ExploitPhpnews26/7/200516/6/2026
Vulnerabilidad de inyección de SQL en auth.php en PHPNews 1.2.5 permite que atacantes remotos ejecuten comandos SQL arbitrarios mediante el parámetro "user" en una petición HTTP POST.
ModificadaMedia (5)1.0%—Frozenplague.net Plague News System6/7/200516/6/2026
SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaMedia (5)1.1%—Frozenplague.net Plague News System6/7/200516/6/2026
delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.
ModificadaMedia (4.3)0.94%—Frozenplague.net Plague News System6/7/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.
ModificadaAlta (7.5)1.1%—Phpnews6/7/200516/6/2026
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.
ModificadaMedia (4.5)0.58%—Cutephp Cutenews9/6/200516/6/2026
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
ModificadaAlta (7.5)1.3%—Dotnetindex Active News Manager31/5/200516/6/2026
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.