Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
1112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.42% | — | Newsx | 31/12/2002 | 16/6/2026 | Format string vulnerability in newsx NNTP client before 1.4.8 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a call to the syslog function. | |
| Modificada | Media (4.3) | 1.2% | — | Carlos Sanchez Valle Mynewsgroups | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the subject of a newsgroup post, which is not properly handled by (1) myarticles.php, (2) search.php, (3) stats.php, or (4) standard.lib.php. | |
| Modificada | Alta (10) | 2.7% | — | Aspbin Newspro | 31/12/2002 | 16/6/2026 | NewsPro 1.01 allows remote attackers to gain unauthorized administrator access by setting their authentication cookie to "logged,true". | |
| Modificada | Alta (7.5) | 1.3% | — | Xqus X-news | 31/12/2002 | 16/6/2026 | x_news.php in X-News (x_news) 1.1 and earlier allows remote attackers to gain administrative privileges by stealing and replaying the md5_password cookie. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter. | |
| Modificada | Alta (7.8) | 1.1% | — | Mysimplenews | 31/12/2002 | 16/6/2026 | MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Xqus X-news | 31/12/2002 | 16/6/2026 | X-News (x_news) 1.1 and earlier allows attackers to authenticate as other users by obtaining the MD5 checksum of the password, e.g. via sniffing or the users.txt data file, and providing it in a cookie. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | PHP Evolution News Evolution | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands via the neurl parameter to (1) backend.php, (2) screen.php, or (3) admin/modules/comment.php. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Mysimplenews | 31/12/2002 | 16/6/2026 | Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, which are inserted into news.php3. | |
| Modificada | Media (5.5) | 0.19% | — | Daansystems Newsreactor | 31/12/2002 | 16/6/2026 | NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Mysimplenews | 31/12/2002 | 16/6/2026 | The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the source of admin.html. | |
| Modificada | Media (5) | 1.2% | — | Markus Triska Cginews | 31/12/2002 | 16/6/2026 | Unknown vulnerability in CGINews before 1.06 allow remote attackers to read arbitrary files via "unfiltered user input." | |
| Modificada | Alta (7.5) | 2.8% | — | Matsushita Research Mnews | 4/10/2002 | 16/6/2026 | Múltiples desbordamientos de búfer en mnews 1.22 y anteriores permiten: a un servidor NNTP remoto ejecutar código arbitrario mediante respuestas largas, o a usuarios locales ganar privilegios mediante argumentos de línea de comando largos (-f, -n, -D, -M, -p), o mediante variables de entorno largas (JNAMES,… | |
| Modificada | Media (5) | 1.3% | — | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote attackers to obtain potentially sensitive information, such as the full server pathname and other configuration settings, via the viewnews command with an invalid database, which leaks the information in error messages. | |
| Modificada | Alta (7.5) | 1.4% | — | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability. | |
| Modificada | Alta (7.6) | 2.2% | — | Linux-sottises Board-tnkLinux-sottises News-tnk | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter. | |
| Modificada | Alta (7.6) | 2.2% | — | Linux-sottises News-tnk | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Sitenews | 31/5/2002 | 16/6/2026 | La función GetPassword en function.php de SiteNews 0.10 y 0.11 permite a atacantes remotos ganar privilegios y añadir usuarios dando un nombre de usuario inexistente y la suma de comprobación (cheksum) MD5 de una contraseña vacía, lo que hace que GetPassword produzca y compare una contraseña en blanco para el usuario… | |
| Modificada | Alta (7.5) | 1.6% | — | Netwin Webnews | 31/5/2002 | 16/6/2026 | El programa CGI Netwin WebNews 1.1k incluye por defecto ciertos nombres de usuarios y contraseñas en texto claro que no pueden ser borrados por el administrador, lo que permite a atacantes remotos ganar privilegios mediante las combianciones de nombres de usuario/contraseña:… | |
| Modificada | Alta (7.5) | 3.3% | — | Netwin Webnews | 31/5/2002 | 16/6/2026 | Desbordamiento de búfer en Netwin WebNews CGI program 1.1, Webnews.exe, permite a atacantes remotos ejecutar código arbitrarior mediante un argumento de grupo largo. | |
| Modificada | Alta (7.5) | 2.3% | — | Avengers News System | 31/5/2002 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en ans.pl en Avenger's New Systems (ANS) 2.11 y anteriosres permite a atacantes remotos determinar la existencia de ficheros arbitrarios o ejecutar cualquier programa Perl en el sistema mediante un .. (punto punto) en el parámetro p, el cual lee el fichero objetivo e… | |
| Modificada | Alta (7.5) | 2.8% | — | Avengers News System | 31/5/2002 | 16/6/2026 | ans.pl en Avenger's New Systems (ANS) 2.11 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante metacaractéres de shell en el parámetro p (plugin) | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Easyscripts Easynews | 31/12/2001 | 16/6/2026 | Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter. |