Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

1112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.0%—Newsphp31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might overlap vector 3 in CVE-2006-3358.
ModificadaAlta (8.5)2.4%—Newsphp31/12/200416/6/2026
Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video files.
ModificadaMedia (4.6)0.33%—Cutephp Cutenews31/12/200416/6/2026
The documentation for CuteNews 1.3.6 and possibly other versions specifies that files under cutenews/data must be manually given world-writable permissions, which allows local users to insert false news, delete news, and possibly gain privileges or have other unknown impact.
ModificadaAlta (10)2.2%—Newsphp31/12/200416/6/2026
NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.
ModificadaAlta (10)4.1%💥 ExploitZaireweb Solutions Newsletter ZWS6/12/200416/6/2026
admin.php de Newsletter ZWS permite a atacantes remotos ganar privilegios administrativos mediante una operación list_user con el parámetro ulevel establecido a 1 (nivel de administrador), lo que lista todos los usuarios y sus contraseñas.
ModificadaMedia (6.8)4.2%💥 ExploitVirtuasystems Virtuanews PRO23/11/200416/6/2026
Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed…
ModificadaMedia (5)8.0%💥 ExploitSkintech Phpnewsmanager23/11/200416/6/2026
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary files via .. (dot dot) sequences in the clang parameter.
ModificadaMedia (4.3)3.6%💥 ExploitPsnews5/9/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.
ModificadaMedia (4.3)3.6%💥 ExploitCutephp Cutenews2/9/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in CuteNews 1.3.6 and earlier allows remote attackers with Administrator, Editor, Journalist or Commenter privileges to inject arbitrary web script or HTML via the mod parameter.
ModificadaAlta (7.5)1.7%—Cutephp Cutenews30/8/200416/6/2026
PHP remote file inclusion vulnerability in CuteNews 1.3.6 and earlier allows remote attackers to execute arbitrary PHP code via the cutepath parameter to (1) show_archives.php or (2) show_news.php.
ModificadaMedia (6.8)3.9%💥 ExploitCutephp Cutenews6/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary script or HTML via the id parameter.
ModificadaAlta (8.8)2.0%💥 ExploitFusionphp Fusion News30/7/200416/6/2026
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.
ModificadaAlta (7.5)2.9%💥 ExploitExpinion.net News Manager LiteAI20/3/200416/6/2026
News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.
ModificadaAlta (7.5)1.7%💥 ExploitExpinion.net News Manager Lite20/3/200416/6/2026
Multiple SQL injection vulnerabilities in News Manager Lite 2.5 allow remote attackers to execute arbitrary SQL code via the (1) ID parameter to more.asp, (2) ID parameter to category_news.asp, or (3) filter parameter to news_sort.asp.
ModificadaMedia (5)3.4%💥 ExploitAshwebstudio Ashnews31/12/200316/6/2026
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php.
ModificadaAlta (7.5)6.9%💥 ExploitCutephp Cutenews31/12/200316/6/2026
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.php, or (3) comments.php.
ModificadaAlta (7.5)2.3%—Newsphp20/10/200316/6/2026
nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication.
ModificadaMedia (5)2.0%—Newsphp20/10/200316/6/2026
nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter.
ModificadaAlta (10)3.2%—Digi-fx Digi-news18/8/200316/6/2026
admin.php en Digi-ads 1.1 permite a atacantes remotos saltarse la autenticación mediante una galletita (cookie) con el nombre de usuario establecido al nombre del administrador, lo que satisface una condición inapropiada en admin.php de no requerir una contraseña correcta.
ModificadaAlta (10)3.2%—Digi-fx Digi-news18/8/200316/6/2026
admin.php en Digi-news 1.1 permite a atacantes remotos saltarse la autenticación mediante una galletita (cookie) con el nombre de usuario establecido al nombre del administrador, lo que satisface una condición inapropiada en admin.php de no requerir una contraseña correcta.
ModificadaMedia (4.3)3.8%💥 ExploitLedscripts.com Lednews7/8/200316/6/2026
Vulnerabildad de secuencias de comandos en sitios cruzados en Lednews 0.7 permite a atacantes remotos insertar script web arbitrario mediante un elemento de noticas.
ModificadaAlta (7.5)2.3%💥 ExploitBlnews2/7/200316/6/2026
objects.inc.php4 en BLNews 2.1.3 permite a atacantes remotos ejecutar código arbitrario mediante un parámetro Server[path] que apunta a código malicioso en un sitio web controlado por el atacante.
ModificadaMedia (5)1.3%—Gkrellm Newsticker12/5/200316/6/2026
El plugin para gkrellm gkrellm-newsticker anteriores a 0.3-3.1 permite a atacantes remotos causar una denegación de servicio (caída) mediante enlaces o elementos de título conteniendo múltiples líneas.
ModificadaAlta (7.5)1.9%—Gkrellm Newsticker12/5/200316/6/2026
El plugin para gkrellm gkrellm-newsticker anteriores a 0.3-3.1 permite a atacantes remotos ejecutar comandos arbitrarios mediante metacaractéres de shell en el título de la noticia de una URI.
ModificadaAlta (7.5)32%—Cgiscript Csnews Professional31/12/200216/6/2026
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
Orbitaley — Vulnerabilidades