Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2717▼ 139 respecto a la semana anterior
Críticas / altas1239▼ 297 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 202 respecto a la semana anterior
–

1113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.5%💥 ExploitEasyscripts Easynews31/12/200116/6/2026
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter.
ModificadaBaja (2.1)0.31%—Easyscripts Easynews31/12/200116/6/2026
easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.
ModificadaMedia (4.3)0.99%—Easyscripts Easynews31/12/200116/6/2026
Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter.
ModificadaAlta (7.5)2.1%—Easyscripts Easynews1/12/200116/6/2026
easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out.
ModificadaAlta (7.5)1.8%—Sourceforge Newsdaemon3/5/200116/6/2026
NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter.
ModificadaAlta (10)3.3%—Mailnews.cgi3/5/200116/6/2026
mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.
ModificadaMedia (5)1.4%—Ibrow News Desk26/3/200116/6/2026
newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.
ModificadaMedia (5)5.6%—Ibrow News Desk26/3/200116/6/2026
Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter.
ModificadaCrítica (9.8)11%💥 ExploitCGI Script Center News Update19/12/200023/9/2026
CGI Script Center News Update 1.1 no valida correctamente la contraseña original de administración de noticias durante una operación de cambio de contraseña, lo que permite a atacantes remotos modificar la contraseña sin conocer la contraseña original.
ModificadaMedia (5)6.2%💥 ExploitGwscripts News Publisher20/10/200016/6/2026
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which allows remote attackers to add new authors by directly posting an HTTP request to the new.cgi program with an addAuthor parameter, and setting the Referer to the news.cgi program.
ModificadaMedia (5)7.8%💥 ExploitNetwin Dnews5/5/200016/6/2026
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.
ModificadaAlta (7.2)1.5%—ISC INNNetscape News ServerSUN SparcRedhat Linux+220/2/199716/6/2026
ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.
ModificadaCrítica (9.8)45%—ISC INNNetscape News ServerBsdi BSD OSCaldera Openlinux+34/12/199616/6/2026
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.