Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%💥 ExploitFrankmancuso Mynews25/2/200916/6/2026
SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.
ModificadaMedia (6.8)0.94%💥 ExploitGregory Kokanosky Phpmynewsletter12/3/200816/6/2026
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earlier allows remote attackers to execute arbitrary SQL commands via the msg_id parameter.
ModificadaMedia (4.3)1.4%💥 ExploitPlanetluc Mynews12/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.
ModificadaMedia (6.8)1.1%💥 ExploitFrank Mancuso Mynews26/6/200716/6/2026
SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie.
ModificadaAlta (10)8.2%💥 ExploitGregory Kokanosky Phpmynewsletter30/4/200716/6/2026
admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a…
ModificadaAlta (10)8.0%💥 ExploitGregory Kokanosky Phpmynewsletter30/4/200716/6/2026
admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action.
ModificadaAlta (10)3.4%💥 ExploitMynewsgroup27/4/200716/6/2026
PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.
ModificadaAlta (7.5)2.3%💥 ExploitMynews12/4/200716/6/2026
PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633.
ModificadaAlta (7.5)3.2%💥 ExploitT-systems Solutions FOR Research Gmbh Mynews31/1/200716/6/2026
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter.
ModificadaAlta (7.5)2.8%💥 ExploitPhpmynews12/10/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cfg_include_dir parameter in (1) disp_form.php3, (2) disp_smileys.php3, (3) little_news.php3, and (4) index.php3 in include/.
ModificadaAlta (7.5)4.4%💥 ExploitCarlos Sanchez Valle MynewsgroupsPHP Layers Menu1/8/200616/6/2026
PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.
ModificadaAlta (7.5)1.3%—Carlos Sanchez Valle Mynewsgroups3/7/200616/6/2026
SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows remote attackers to execute arbitrary SQL commands via the grp_id parameter.
ModificadaAlta (7.5)2.3%💥 ExploitAspburst Mynewsletter7/6/200616/6/2026
Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.
ModificadaMedia (4.3)1.9%💥 ExploitPlanetluc Mynews5/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters.
ModificadaAlta (7.5)3.0%💥 ExploitGregory Kokanosky Phpmynewsletter31/12/200216/6/2026
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter.
ModificadaMedia (4.3)1.2%—Carlos Sanchez Valle Mynewsgroups31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the subject of a newsgroup post, which is not properly handled by (1) myarticles.php, (2) search.php, (3) stats.php, or (4) standard.lib.php.
Orbitaley — Vulnerabilidades