Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)48%—News System Project News System7/4/201717/6/2026
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand for order and OrderByAllowed.
ModificadaAlta (7.5)1.2%💥 ExploitTiger PHP News System29/1/200816/6/2026
SQL injection vulnerability in index.php in Tiger Php News System (TPNS) 1.0b and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newscat action.
ModificadaAlta (7.5)2.2%💥 ExploitX-ice News System13/3/200716/6/2026
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)4.2%💥 ExploitVirtualsystem Vs-news-system21/2/200716/6/2026
PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.
ModificadaAlta (9.3)1.9%—Virtualsystem Vs-news-system21/2/200716/6/2026
PHP remote file inclusion vulnerability in tpl/header.php in VirtualSystem VS-News-System 1.2.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter. NOTE: the provenance of this information is unknown; the details are obtained…
ModificadaAlta (7.5)1.2%—Lucas Rodriguez SAN Pedro YET Another News System15/11/200616/6/2026
Multiple SQL injection vulnerabilities in the login_user function in yans.func.php in Lucas Rodriguez San Pedro Yet Another News System (YANS) 0.2b allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.
ModificadaAlta (7.5)2.5%💥 ExploitPnews Systems Pnews27/9/200616/6/2026
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter.
ModificadaMedia (4.3)1.9%💥 ExploitSitebeater News SystemAI5/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in archive.asp in SiteBeater News System 4.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the sKeywords parameter.
ModificadaAlta (7.5)1.9%—WEB Content Management News System7/8/200516/6/2026
Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.
ModificadaMedia (4.3)1.8%💥 ExploitWEB Content Management News System7/8/200516/6/2026
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
ModificadaMedia (5)1.1%—Frozenplague.net Plague News System6/7/200516/6/2026
delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.
ModificadaMedia (4.3)0.94%—Frozenplague.net Plague News System6/7/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.
ModificadaMedia (5)1.0%—Frozenplague.net Plague News System6/7/200516/6/2026
SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)2.8%—Avengers News System31/5/200216/6/2026
ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.
ModificadaAlta (7.5)2.3%—Avengers News System31/5/200216/6/2026
Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute the line using Perl's…
Orbitaley — Vulnerabilidades