Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2779▼ 337 respecto a la semana anterior
Críticas / altas1284▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▼ 88 respecto a la semana anterior
1112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.5) | 0.58% | — | Cutephp Cutenews | 9/6/2005 | 16/6/2026 | Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file. | |
| Modificada | Alta (7.5) | 1.3% | — | Dotnetindex Active News Manager | 31/5/2005 | 16/6/2026 | SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password. | |
| Modificada | Alta (7.5) | 1.3% | — | Distinct WEB Creations Newsletterez | 25/5/2005 | 16/6/2026 | SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Media (4.3) | 1.0% | — | 1two News | 14/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables. | |
| Modificada | Media (5) | 1.1% | — | 1two News | 14/5/2005 | 16/6/2026 | 1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Darrel Oneil ASP Virtual News Manager | 11/5/2005 | 16/6/2026 | SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Media (5) | 1.3% | — | NewsbbruiserAI | 2/5/2005 | 16/6/2026 | Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments." | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | THE Rusted Gate TRG News | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Czaries Network Czarnews | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a cut-and-paste error from the wrong section of… | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Mcnews | 2/5/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | China-on-site Flexphpnews | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands via the newsid parameter. | |
| Modificada | Alta (10) | 7.7% | 💥 Exploit | Newsscript.co.uk Newsscript | 2/5/2005 | 16/6/2026 | newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin. | |
| Modificada | Media (4.3) | 0.94% | — | Cutephp CutenewsAI | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in show.inc.php in cuteNews 1.3.6 allows remote attackers to inject arbitrary HTML, web script, and PHP code via the (1) CLIENT-IP or (2) X-FORWARDED-FOR header in an HTTP POST request to show_news.php. | |
| Modificada | Media (5) | 4.2% | 💥 Exploit | PHP Arena Panews | 2/5/2005 | 16/6/2026 | admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2) $form[autoapprove] parameters, which are written to config.php. | |
| Modificada | Alta (7.5) | 1.1% | — | PHP Arena Panews | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in auth.php in paNews 2.0.4b allows remote attackers to execute arbitrary SQL via the mysql_prefix parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | AcnewsAI | 13/4/2005 | 16/6/2026 | SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters. | |
| Modificada | Media (6.8) | 1.8% | — | Phparena Panews | 30/3/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en comment.php para paNews 2.0b4 de PHP Arena permite a atacantes remotos la inyección de HTML arbitrario y scripts web, mediante el parámetro showpost. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Mcnews | 8/3/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Phpnews | 1/3/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Newspost | 1/2/2005 | 16/6/2026 | Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character. | |
| Modificada | Alta (7.5) | 1.7% | — | Blackboard Internet Newsboard System | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Phpnews | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php. | |
| Modificada | Alta (7.2) | 0.46% | — | Aj-forkCutephp Cutenews | 31/12/2004 | 16/6/2026 | The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator. | |
| Modificada | Alta (7.5) | 9.3% | 💥 Exploit | Hotnews | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP code via the (1) config[header] parameter to hotnews-engine.inc.php3 or (2) config[incdir] parameter to hnmain.inc.php3. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Expinion.net News Manager Lite | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp. |