Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2786▼ 305 respecto a la semana anterior
Críticas / altas1290▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | News2net | 2/11/2005 | 16/6/2026 | SQL injection vulnerability in index.php in News2Net 3.0.0.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Crítica (9.8) | 2.3% | — | Archilles Newsworld | 2/11/2005 | 16/6/2026 | admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and specifying the hash in the pwd argument. | |
| Modificada | Alta (7.5) | 1.5% | — | Archilles Newsworld | 2/11/2005 | 16/6/2026 | Archilles Newsworld before 1.5.0-rc1 stores (1) account.nwd and (2) session.nwd under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames, hashed passwords, and session IDs, and gain privileges. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | Utopia Software Utopia News PRO | 14/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Utopiasoftware News PROAI | 14/10/2005 | 16/6/2026 | SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Cutephp Cutenews | 21/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CuteNews allows remote attackers to inject arbitrary web script or HTML via the mod parameter to index.php. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Cutephp Cutenews | 21/9/2005 | 16/6/2026 | Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php. | |
| Modificada | Media (5) | 1.2% | — | Stylemotion WEB News | 14/9/2005 | 16/6/2026 | WEB//NEWS 1.4 allows remote attackers to obtain sensitive information via a direct request to files in the actions directory, which reveal the path in an error message, as demonstrated using cat.add.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Stylemotion WEB News | 14/9/2005 | 16/6/2026 | SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Unclassified Newsboard | 8/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web script or HTML via the description field. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpfreenews | 23/8/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Phpfreenews | 23/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchResults.php. | |
| Modificada | Media (5) | 1.2% | — | Acnews | 23/8/2005 | 16/6/2026 | ACNews stores the database in a file under the web document root with a db.inc extension and insufficient access control, which allows remote attackers to obtain sensitive information such as the full pathname of the server. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | WEB Content Management News System | 7/8/2005 | 16/6/2026 | Vulnerabilidad de scritps en sitios cruzados (XSS) en Web Content Management News System permite a atacantes remotos inyectar script web arbitrario o HTML mediante el parámetro strRootpath de validsession.php o el parámetro strTable de Admin/News/List.php | |
| Modificada | Alta (7.5) | 1.9% | — | WEB Content Management News System | 7/8/2005 | 16/6/2026 | Web Content Management News System permite a atacantes remotos crear cuentas de su elección y ganar privilegios mediante una petición directa a Admin/Users/AddModifyInput.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Silver-scripts Silvernews | 5/8/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en SilverNews 2.0.3 permite que atacantes remotos ejecuten comandos SQL en el campo "user" de la página de login del panel de control de administración. | |
| Modificada | Media (4.3) | 0.99% | — | Cutephp Cutenews | 27/7/2005 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en CuteNews 1.3.6 permite que atacantes remotos inyecten script web arbitrario o HTML mediante 1) el parámetro "lastusername" en index.php o 2) el parámetro "selected_search_arch" en search.php. | |
| Modificada | Media (5) | 1.3% | — | Cutephp Cutenews | 27/7/2005 | 16/6/2026 | show_news.php en CuteNews 1.3.6 permite que atacantes remotos obtengan el path absoluto al servidor mediante un parámetro "archive" inválido. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpnews | 26/7/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en auth.php en PHPNews 1.2.5 permite que atacantes remotos ejecuten comandos SQL arbitrarios mediante el parámetro "user" en una petición HTTP POST. | |
| Modificada | Media (5) | 1.0% | — | Frozenplague.net Plague News System | 6/7/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Media (5) | 1.1% | — | Frozenplague.net Plague News System | 6/7/2005 | 16/6/2026 | delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Frozenplague.net Plague News System | 6/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpnews | 6/7/2005 | 16/6/2026 | SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter. | |
| Modificada | Media (4.5) | 0.58% | — | Cutephp Cutenews | 9/6/2005 | 16/6/2026 | Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file. | |
| Modificada | Alta (7.5) | 1.3% | — | Dotnetindex Active News Manager | 31/5/2005 | 16/6/2026 | SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password. |