Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2779▼ 337 respecto a la semana anterior
Críticas / altas1284▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▼ 88 respecto a la semana anterior
–

1112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.5)0.58%—Cutephp Cutenews9/6/200516/6/2026
Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.
ModificadaAlta (7.5)1.3%—Dotnetindex Active News Manager31/5/200516/6/2026
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.
ModificadaAlta (7.5)1.3%—Distinct WEB Creations Newsletterez25/5/200516/6/2026
SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.
ModificadaMedia (4.3)1.0%—1two News14/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables.
ModificadaMedia (5)1.1%—1two News14/5/200516/6/2026
1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php.
ModificadaAlta (7.5)1.2%—Darrel Oneil ASP Virtual News Manager11/5/200516/6/2026
SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.
ModificadaMedia (5)1.3%—NewsbbruiserAI2/5/200516/6/2026
Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."
ModificadaAlta (7.5)2.5%💥 ExploitTHE Rusted Gate TRG News2/5/200516/6/2026
PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php.
ModificadaAlta (7.5)11%💥 ExploitCzaries Network Czarnews2/5/200516/6/2026
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of…
ModificadaAlta (7.5)3.0%💥 ExploitMcnews2/5/200516/6/2026
PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.
ModificadaAlta (7.5)2.2%💥 ExploitChina-on-site Flexphpnews2/5/200516/6/2026
SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
ModificadaAlta (10)7.7%💥 ExploitNewsscript.co.uk Newsscript2/5/200516/6/2026
newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.
ModificadaMedia (4.3)0.94%—Cutephp CutenewsAI2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in show.inc.php in cuteNews 1.3.6 allows remote attackers to inject arbitrary HTML, web script, and PHP code via the (1) CLIENT-IP or (2) X-FORWARDED-FOR header in an HTTP POST request to show_news.php.
ModificadaMedia (5)4.2%💥 ExploitPHP Arena Panews2/5/200516/6/2026
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php.
ModificadaAlta (7.5)1.1%—PHP Arena Panews2/5/200516/6/2026
SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter.
ModificadaAlta (7.5)1.1%💥 ExploitAcnewsAI13/4/200516/6/2026
SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
ModificadaMedia (6.8)1.8%—Phparena Panews30/3/200516/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en comment.php para paNews 2.0b4 de PHP Arena permite a atacantes remotos la inyección de HTML arbitrario y scripts web, mediante el parámetro showpost.
ModificadaAlta (7.5)2.8%💥 ExploitMcnews8/3/200516/6/2026
PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.
ModificadaMedia (5)2.6%💥 ExploitPhpnews1/3/200516/6/2026
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.
ModificadaAlta (7.5)16%💥 ExploitNewspost1/2/200516/6/2026
Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.
ModificadaAlta (7.5)1.7%—Blackboard Internet Newsboard System31/12/200416/6/2026
PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.
ModificadaAlta (7.5)1.2%—Phpnews31/12/200416/6/2026
SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php.
ModificadaAlta (7.2)0.46%—Aj-forkCutephp Cutenews31/12/200416/6/2026
The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.
ModificadaAlta (7.5)9.3%💥 ExploitHotnews31/12/200416/6/2026
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3.
ModificadaMedia (4.3)2.2%💥 ExploitExpinion.net News Manager Lite31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.
Orbitaley — Vulnerabilidades