Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
1112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Newsphp | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358. | |
| Modificada | Alta (8.5) | 2.4% | — | Newsphp | 31/12/2004 | 16/6/2026 | Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files. | |
| Modificada | Media (4.6) | 0.33% | — | Cutephp Cutenews | 31/12/2004 | 16/6/2026 | The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact. | |
| Modificada | Alta (10) | 2.2% | — | Newsphp | 31/12/2004 | 16/6/2026 | NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value. | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Zaireweb Solutions Newsletter ZWS | 6/12/2004 | 16/6/2026 | admin.php de Newsletter ZWS permite a atacantes remotos ganar privilegios administrativos mediante una operación list_user con el parámetro ulevel establecido a 1 (nivel de administrador), lo que lista todos los usuarios y sus contraseñas. | |
| Modificada | Media (6.8) | 4.2% | 💥 Exploit | Virtuasystems Virtuanews PRO | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed… | |
| Modificada | Media (5) | 8.0% | 💥 Exploit | Skintech Phpnewsmanager | 23/11/2004 | 16/6/2026 | Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Psnews | 5/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Cutephp Cutenews | 2/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Cutephp Cutenews | 30/8/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php. | |
| Modificada | Media (6.8) | 3.9% | 💥 Exploit | Cutephp Cutenews | 6/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter. | |
| Modificada | Alta (8.8) | 2.0% | 💥 Exploit | Fusionphp Fusion News | 30/7/2004 | 16/6/2026 | Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Expinion.net News Manager LiteAI | 20/3/2004 | 16/6/2026 | News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Expinion.net News Manager Lite | 20/3/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Ashwebstudio Ashnews | 31/12/2003 | 16/6/2026 | PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php. | |
| Modificada | Alta (7.5) | 6.9% | 💥 Exploit | Cutephp Cutenews | 31/12/2003 | 16/6/2026 | PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php. | |
| Modificada | Alta (7.5) | 2.3% | — | Newsphp | 20/10/2003 | 16/6/2026 | nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication. | |
| Modificada | Media (5) | 2.0% | — | Newsphp | 20/10/2003 | 16/6/2026 | nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter. | |
| Modificada | Alta (10) | 3.2% | — | Digi-fx Digi-news | 18/8/2003 | 16/6/2026 | admin.php en Digi-ads 1.1 permite a atacantes remotos saltarse la autenticación mediante una galletita (cookie) con el nombre de usuario establecido al nombre del administrador, lo que satisface una condición inapropiada en admin.php de no requerir una contraseña correcta. | |
| Modificada | Alta (10) | 3.2% | — | Digi-fx Digi-news | 18/8/2003 | 16/6/2026 | admin.php en Digi-news 1.1 permite a atacantes remotos saltarse la autenticación mediante una galletita (cookie) con el nombre de usuario establecido al nombre del administrador, lo que satisface una condición inapropiada en admin.php de no requerir una contraseña correcta. | |
| Modificada | Media (4.3) | 3.8% | 💥 Exploit | Ledscripts.com Lednews | 7/8/2003 | 16/6/2026 | Vulnerabildad de secuencias de comandos en sitios cruzados en Lednews 0.7 permite a atacantes remotos insertar script web arbitrario mediante un elemento de noticas. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Blnews | 2/7/2003 | 16/6/2026 | objects.inc.php4 en BLNews 2.1.3 permite a atacantes remotos ejecutar código arbitrario mediante un parámetro Server[path] que apunta a código malicioso en un sitio web controlado por el atacante. | |
| Modificada | Media (5) | 1.3% | — | Gkrellm Newsticker | 12/5/2003 | 16/6/2026 | El plugin para gkrellm gkrellm-newsticker anteriores a 0.3-3.1 permite a atacantes remotos causar una denegación de servicio (caída) mediante enlaces o elementos de título conteniendo múltiples líneas. | |
| Modificada | Alta (7.5) | 1.9% | — | Gkrellm Newsticker | 12/5/2003 | 16/6/2026 | El plugin para gkrellm gkrellm-newsticker anteriores a 0.3-3.1 permite a atacantes remotos ejecutar comandos arbitrarios mediante metacaractéres de shell en el título de la noticia de una URI. | |
| Modificada | Alta (7.5) | 32% | — | Cgiscript Csnews Professional | 31/12/2002 | 16/6/2026 | csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. |