Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | — | Phpeasynews Phpeasyblog | 23/6/2008 | 16/6/2026 | SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Myiosoft Easynews | 2/4/2008 | 16/6/2026 | SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL commands via the read parameter in an edp_Help_Internal_News action. | |
| Modificada | Alta (7.5) | 3.1% | — | Myiosoft Easynews | 2/4/2008 | 16/6/2026 | Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Myiosoft Easynews | 2/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_pupublish action. | |
| Modificada | Media (4.3) | 1.1% | — | Stphp Easynews | 21/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to inject arbitrary web script or HTML via a news post, which is stored in news/ without sanitization. | |
| Modificada | Media (5) | 1.2% | — | Stphp Easynews | 21/6/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin password via (1) a certain HTML form that is posted automatically by JavaScript or (2) a news post. | |
| Modificada | Alta (7.8) | 3.1% | — | Stphp Easynews | 31/12/2006 | 16/6/2026 | STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, email addresses, and password hashes via a direct request for data/users.txt. | |
| Modificada | Media (5.1) | 3.9% | — | PHP Outburst Easynews | 20/10/2006 | 16/6/2026 | admin.php in PHP Outburst Easynews 4.4.1 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication, and gain the ability to execute arbitrary code, via the en_login_id parameter. | |
| Modificada | Baja (2.1) | 0.31% | — | Easyscripts Easynews | 31/12/2001 | 16/6/2026 | easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access. | |
| Modificada | Media (4.3) | 0.99% | — | Easyscripts Easynews | 31/12/2001 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the comments action in index.php in easyNews 1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the zeit parameter. | |
| Modificada | Media (5) | 2.5% | — | Easyscripts Easynews | 31/12/2001 | 16/6/2026 | Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify news.dat, template.dat and possibly other files via a ".." in the cid parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Easyscripts Easynews | 1/12/2001 | 16/6/2026 | easyScripts easyNews 1.5 allows remote attackers to obtain the full path of the web root via a view request with a non-integer news message id field, which leaks the path in a PHP error message when the script times out. |