Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.5%—Xigla Absolute News Manager.net14/7/200916/6/2026
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
ModificadaMedia (4.3)1.3%—Virtuenetz Virtue News Manager9/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
ModificadaAlta (7.5)1.0%—Virtuenetz Virtue News Manager9/6/200916/6/2026
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.
ModificadaAlta (7.5)1.0%—Dreamlevels Dreamnews Manager16/7/200816/6/2026
SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaBaja (3.5)1.0%—Xigla Absolute News Manager XE18/6/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute News Manager XE 3.2 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) pblname and (2) text parameters to (a) admin/search.asp, (3) name parameter to (b) admin/publishers.asp, and other unspecified vectors…
ModificadaMedia (6.5)1.2%—Xigla Absolute News Manager XE18/6/200816/6/2026
SQL injection vulnerability in search.asp in Xigla Absolute News Manager XE 3.2 allows remote authenticated administrators to execute arbitrary SQL commands via the orderby parameter.
ModificadaAlta (7.5)2.3%—Avalonnet News Manager19/5/200816/6/2026
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the read_xml_include parameter.
ModificadaAlta (7.5)2.4%—News Manager19/5/200816/6/2026
News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (2) login/info.php.
ModificadaAlta (7.5)1.00%—News Manager19/5/200816/6/2026
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.
ModificadaMedia (5)2.7%—News Manager19/5/200816/6/2026
Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
ModificadaAlta (7.5)2.9%—Xigla Absolute News Manager.net7/12/200716/6/2026
Multiple SQL injection vulnerabilities in xlaabsolutenm.aspx in Absolute News Manager.NET 5.1 allow remote attackers to execute arbitrary SQL commands via the (1) z, (2) pz, (3) ord, and (4) sort parameters.
ModificadaMedia (5)8.4%—Xigla Absolute News Manager.net7/12/200716/6/2026
Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
ModificadaMedia (5)2.7%—Xigla Absolute News Manager.net7/12/200716/6/2026
Absolute News Manager.NET 5.1 allows remote attackers to obtain sensitive information via a direct request to getpath.aspx, which reveals the installation path in an error message.
ModificadaMedia (4.3)2.3%—Xigla Absolute News Manager.net7/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Absolute News Manager.NET 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) rmore parameter to xlaabsolutenm.aspx and the (2) template parameter to pages/default.aspx.
ModificadaMedia (6.8)2.0%—News Manager Deluxe26/4/200716/6/2026
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.
ModificadaMedia (4.3)1.8%—Built2go News Manager Blog3/3/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) cid, (2) uid, and (3) nid parameters to (a) news.php, and the nid parameter to (b) rating.php.
ModificadaMedia (6.8)2.1%—Expinion.net Inews PublisherExpinion.net News Manager4/12/200616/6/2026
SQL injection vulnerability in articles.asp in Expinion.net iNews (1) Publisher (iNP) 2.5 and earlier, and possibly (2) News Manager, allows remote attackers to execute arbitrary SQL commands via the ex parameter. NOTE: early reports of this issue reported it as XSS, but this was erroneous. The original report was for…
ModificadaAlta (7.5)3.7%—Dotnetindex Active News Manager24/11/200616/6/2026
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) catID parameter to activeNews_categories.asp, the (2) articleID parameter to activeNews_comments.asp, or the (3) query parameter to activenews_search.asp.
ModificadaAlta (7.5)1.4%—Dotnetindex Active News Manager24/11/200616/6/2026
Multiple SQL injection vulnerabilities in ActiveNews Manager allow remote attackers to execute arbitrary SQL commands via the (1) articleID parameter to activenews_view.asp or the (2) page parameter to default.asp. NOTE: the activeNews_categories.asp and activeNews_comments.asp vectors are already covered by…
ModificadaMedia (4.3)1.9%—Dotnetindex Active News Manager24/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in activenews_search.asp in ActiveNews Manager allows remote attackers to inject arbitrary web script or HTML via the query parameter.
ModificadaMedia (6.4)2.9%—PRE Projects PRE News Manager2/6/200616/6/2026
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php.…
ModificadaMedia (5.8)2.8%—PRE Projects PRE News Manager31/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Pre News Manager 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and…
ModificadaAlta (7.5)1.3%—Dotnetindex Active News Manager31/5/200516/6/2026
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.
ModificadaAlta (7.5)1.2%—Darrel Oneil ASP Virtual News Manager11/5/200516/6/2026
SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.
ModificadaMedia (4.3)2.2%—Expinion.net News Manager Lite31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in News Manager Lite 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to comment_add.asp, (2) search parameter to search.asp, or (3) n parameter to category_news_headline.asp.