Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2717▼ 139 respecto a la semana anterior
Críticas / altas1239▼ 297 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 202 respecto a la semana anterior
1113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.5% | 💥 Exploit | Easyscripts Easynews | 31/12/2001 | 16/6/2026 | Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter. | |
| Modificada | Baja (2.1) | 0.31% | — | Easyscripts Easynews | 31/12/2001 | 16/6/2026 | easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access. | |
| Modificada | Media (4.3) | 0.99% | — | Easyscripts Easynews | 31/12/2001 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Easyscripts Easynews | 1/12/2001 | 16/6/2026 | easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out. | |
| Modificada | Alta (7.5) | 1.8% | — | Sourceforge Newsdaemon | 3/5/2001 | 16/6/2026 | NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter. | |
| Modificada | Alta (10) | 3.3% | — | Mailnews.cgi | 3/5/2001 | 16/6/2026 | mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters. | |
| Modificada | Media (5) | 1.4% | — | Ibrow News Desk | 26/3/2001 | 16/6/2026 | newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters. | |
| Modificada | Media (5) | 5.6% | — | Ibrow News Desk | 26/3/2001 | 16/6/2026 | Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | CGI Script Center News Update | 19/12/2000 | 23/9/2026 | CGI Script Center News Update 1.1 no valida correctamente la contraseña original de administración de noticias durante una operación de cambio de contraseña, lo que permite a atacantes remotos modificar la contraseña sin conocer la contraseña original. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Gwscripts News Publisher | 20/10/2000 | 16/6/2026 | news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program. | |
| Modificada | Media (5) | 7.8% | 💥 Exploit | Netwin Dnews | 5/5/2000 | 16/6/2026 | Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag. | |
| Modificada | Alta (7.2) | 1.5% | — | ISC INNNetscape News ServerSUN SparcRedhat Linux+2 | 20/2/1997 | 16/6/2026 | ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN. | |
| Modificada | Crítica (9.8) | 45% | — | ISC INNNetscape News ServerBsdi BSD OSCaldera Openlinux+3 | 4/12/1996 | 16/6/2026 | Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. |