Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.33% | — | Mm-breaking News Project Mm-breaking News | 12/9/2024 | 17/6/2026 | The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Analizada | Media (6.1) | 0.21% | — | Mm-breaking News Project Mm-breaking News | 12/9/2024 | 17/6/2026 | The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Modificada | Media (6.5) | 0.31% | — | Moodle-block Sitenews Project Moodle-block Sitenews | 27/12/2022 | 17/6/2026 | A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this… | |
| Modificada | Alta (7.2) | 0.67% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications. | |
| Modificada | Media (5.3) | 0.80% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data. | |
| Modificada | Media (6.1) | 0.59% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS. | |
| Modificada | Crítica (9.8) | 1.00% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection. | |
| Modificada | Baja (3.5) | 0.95% | — | Taxonews Project Taxonews | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Taxonews module before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a term name in a block. | |
| Modificada | Media (5.4) | 0.27% | — | Thailand Investor News Project Thailand Investor News | 20/10/2014 | 17/6/2026 | The Thailand Investor News (aka nudecreative.thaistock.set) application 1.39s for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.3% | — | News Project News | 3/10/2014 | 17/6/2026 | The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue. | |
| Modificada | Media (5.4) | 0.27% | — | Oman News Project Oman News | 29/9/2014 | 17/6/2026 | The Oman News (aka com.oman.news.rmtzlnbuooordciw) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Al-ahsa News Project Al-ahsa News | 27/9/2014 | 17/6/2026 | The Al-Ahsa News (aka com.alahsa.news) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Techradar News Project Techradar News | 25/9/2014 | 17/6/2026 | The TechRadar News (aka com.techradar.news) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 1.1% | — | Utopiasoftware News PRO | 14/8/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts. | |
| Modificada | Baja (2.6) | 1.3% | — | Utopia Software Utopia News PRO | 19/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter. | |
| Modificada | Alta (7.5) | 8.6% | — | Reamday Enterprises Magic News PRO | 15/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | Utopia Software Utopia News PRO | 14/12/2005 | 16/6/2026 | Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in… | |
| Modificada | Media (4.3) | 2.6% | — | Utopia Software Utopia News PRO | 14/10/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php. | |
| Modificada | Alta (7.5) | 1.8% | — | Utopiasoftware News PROAI | 14/10/2005 | 16/6/2026 | SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter. | |
| Modificada | Media (6.8) | 4.2% | — | Virtuasystems Virtuanews PRO | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed… | |
| Modificada | Alta (7.5) | 32% | — | Cgiscript Csnews Professional | 31/12/2002 | 16/6/2026 | csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. |