Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 48% | — | News System Project News System | 7/4/2017 | 17/6/2026 | SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Tiger PHP News System | 29/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newscat action. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | X-ice News System | 13/3/2007 | 16/6/2026 | SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 4.2% | 💥 Exploit | Virtualsystem Vs-news-system | 21/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter. | |
| Modificada | Alta (9.3) | 1.9% | — | Virtualsystem Vs-news-system | 21/2/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in tpl/header.php in VirtualSystem VS-News-System 1.2.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 1.2% | — | Lucas Rodriguez SAN Pedro YET Another News System | 15/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Pnews Systems Pnews | 27/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Sitebeater News SystemAI | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | WEB Content Management News System | 7/8/2005 | 16/6/2026 | Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | WEB Content Management News System | 7/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php. | |
| Modificada | Media (5) | 1.1% | — | Frozenplague.net Plague News System | 6/7/2005 | 16/6/2026 | delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter. | |
| Modificada | Media (4.3) | 0.94% | — | Frozenplague.net Plague News System | 6/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter. | |
| Modificada | Media (5) | 1.0% | — | Frozenplague.net Plague News System | 6/7/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 2.8% | — | Avengers News System | 31/5/2002 | 16/6/2026 | ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Avengers News System | 31/5/2002 | 16/6/2026 | Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl's… |