Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Frankmancuso Mynews | 25/2/2009 | 16/6/2026 | SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters. | |
| Modificada | Media (6.8) | 0.94% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 12/3/2008 | 16/6/2026 | SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earlier allows remote attackers to execute arbitrary SQL commands via the msg_id parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Planetluc Mynews | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Frank Mancuso Mynews | 26/6/2007 | 16/6/2026 | SQL injection vulnerability in admin.php in MyNews 0.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the authacc cookie. | |
| Modificada | Alta (10) | 8.2% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 30/4/2007 | 16/6/2026 | admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a… | |
| Modificada | Alta (10) | 8.0% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 30/4/2007 | 16/6/2026 | admin/index.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier provides access to configuration modification before login, which allows remote attackers to cause a denial of service (loss of configuration data), and possibly perform direct static code injection, via a saveGlobalconfig action. | |
| Modificada | Alta (10) | 3.4% | 💥 Exploit | Mynewsgroup | 27/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include.php in MyNewsGroups :) allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Mynews | 12/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include/blocks/week_events.php in MyNews 4.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter, a different vector than CVE-2007-0633. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | T-systems Solutions FOR Research Gmbh Mynews | 31/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myNewsConf[path][sys][index] parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Phpmynews | 12/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cfg_include_dir parameter in (1) disp_form.php3, (2) disp_smileys.php3, (3) little_news.php3, and (4) index.php3 in include/. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Carlos Sanchez Valle MynewsgroupsPHP Layers Menu | 1/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Carlos Sanchez Valle Mynewsgroups | 3/7/2006 | 16/6/2026 | SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows remote attackers to execute arbitrary SQL commands via the grp_id parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Aspburst Mynewsletter | 7/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Planetluc Mynews | 5/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Gregory Kokanosky Phpmynewsletter | 31/12/2002 | 16/6/2026 | PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute arbitrary PHP code via the l parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Carlos Sanchez Valle Mynewsgroups | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyNewsGroups 0.4 and 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the subject of a newsgroup post, which is not properly handled by (1) myarticles.php, (2) search.php, (3) stats.php, or (4) standard.lib.php. |