Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.33%—Mm-breaking News Project Mm-breaking News12/9/202417/6/2026
The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
AnalizadaMedia (6.1)0.21%—Mm-breaking News Project Mm-breaking News12/9/202417/6/2026
The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
ModificadaMedia (6.5)0.31%—Moodle-block Sitenews Project Moodle-block Sitenews27/12/202217/6/2026
A vulnerability was found in moodle-block_sitenews 1.0. It has been classified as problematic. This affects the function get_content of the file block_sitenews.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.1 is able to address this…
ModificadaAlta (7.2)0.67%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.
ModificadaMedia (5.3)0.80%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.
ModificadaMedia (6.1)0.59%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
ModificadaCrítica (9.8)1.00%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
ModificadaBaja (3.5)0.95%—Taxonews Project Taxonews21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Taxonews module before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a term name in a block.
ModificadaMedia (5.4)0.27%—Thailand Investor News Project Thailand Investor News20/10/201417/6/2026
The Thailand Investor News (aka nudecreative.thaistock.set) application 1.39s for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)1.3%—News Project News3/10/201417/6/2026
The News (tt_news) extension before 3.5.2 for TYPO3 allows remote attackers to have unspecified impact via vectors related to an "insecure unserialize" issue.
ModificadaMedia (5.4)0.27%—Oman News Project Oman News29/9/201417/6/2026
The Oman News (aka com.oman.news.rmtzlnbuooordciw) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Al-ahsa News Project Al-ahsa News27/9/201417/6/2026
The Al-Ahsa News (aka com.alahsa.news) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Techradar News Project Techradar News25/9/201417/6/2026
The TechRadar News (aka com.techradar.news) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.8)1.1%—Utopiasoftware News PRO14/8/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in upload/users.php in Utopia News Pro (UNP) 1.4.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts.
ModificadaBaja (2.6)1.3%—Utopia Software Utopia News PRO19/6/200716/6/2026
Cross-site scripting (XSS) vulnerability in login.php in Utopia News Pro 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the password parameter.
ModificadaAlta (7.5)8.6%—Reamday Enterprises Magic News PRO15/9/200616/6/2026
PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter.
ModificadaAlta (7.5)1.8%—Utopia Software Utopia News PRO14/12/200516/6/2026
Multiple "potential" SQL injection vulnerabilities in Utopia News Pro (UNP) 1.1.4 might allow remote attackers to execute arbitrary SQL commands via (1) the newsid parameter in editnews.php, (2) the catid and question parameters in faq.php, (3) the poster parameter in postnews.php, (4) the tempid parameter in…
ModificadaMedia (4.3)2.6%—Utopia Software Utopia News PRO14/10/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the sitetitle parameter in header.php and (2) the version and (3) query_count parameters in footer.php.
ModificadaAlta (7.5)1.8%—Utopiasoftware News PROAI14/10/200516/6/2026
SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.
ModificadaMedia (6.8)4.2%—Virtuasystems Virtuanews PRO23/11/200416/6/2026
Cross-site scripting (XSS) vulnerability in VirtuaNews Admin Panel Pro 1.0.3 allows remote attackers to execute arbitrary script as other users via (1) the mainnews parameter in admin.php, (2) the expand parameter in admin.php, (3) the id parameter in admin.php, (4) the catid parameter in admin.php, or (5) an unnamed…
ModificadaAlta (7.5)32%—Cgiscript Csnews Professional31/12/200216/6/2026
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.