Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.9) | 0.28% | — | Transbyte Scooper News | 29/8/2025 | 17/6/2026 | A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.hatsune.eagleee. This manipulation causes improper export of android application components. The attack requires local access. The exploit… | |
| Analizada | Baja (2.1) | 0.66% | — | Isolucoesweb Solucoescoop | 6/6/2025 | 17/6/2026 | A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250516. It has been classified as problematic. This affects an unknown part of the file /sys/up.upload.php of the component Profile Information Update. The manipulation of the argument nomeArquivo leads to path traversal. It is possible to initiate the… | |
| Analizada | Baja (2) | 0.35% | — | Isolucoesweb Solucoescoop | 6/6/2025 | 17/6/2026 | A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250519 and classified as problematic. Affected by this issue is some unknown functionality of the file /fluxos-dashboard of the component Flow Handler. The manipulation of the argument Descrição da solicitação leads to cross site scripting. The attack may… | |
| Modificada | Media (4.8) | 0.54% | — | Wpscoop Imageinject | 26/12/2022 | 17/6/2026 | The ImageInject WordPress plugin through 1.17 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Alta (7.8) | 0.65% | — | Sourcefabric Newscoop | 19/5/2020 | 17/6/2026 | Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/ path. | |
| Modificada | Alta (8.8) | 0.73% | — | Wpscoop Imageinject | 8/1/2018 | 17/6/2026 | The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php. | |
| Modificada | Media (4.8) | 0.80% | — | Wpscoop Imageinject | 8/1/2018 | 17/6/2026 | The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php. | |
| Modificada | Media (5.4) | 0.33% | — | Getscoop Kontan Kiosk | 20/10/2014 | 17/6/2026 | The Kontan Kiosk (aka com.appsfoundry.scoopwl.id.kontankiosk) application @7F07025E for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.8% | — | Sourcefabric Newscoop | 22/2/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to application/modules/admin/controllers/LanguagesController.php or (2) user parameter to… | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/login.php in Newscoop before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via the f_user_name parameter. | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4.x before 4 RC4 allow remote attackers to inject arbitrary web script or HTML via the (1) Back parameter to admin/ad.php, or the (2) token or (3) f_email parameter to admin/password_check_token.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | SQL injection vulnerability in admin/country/edit.php in Newscoop before 3.5.5 and 4.x before 4 RC4 allows remote attackers to execute arbitrary SQL commands via the f_country_code parameter. | |
| Modificada | Media (6.8) | 5.6% | 💥 Exploit | Sourcefabric Newscoop | 27/8/2012 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to (1) include/phorum_load.php, (2) conf/install_conf.php, or (3)… | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Commercial Interactive Media Scoop | 22/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SCOOP! 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword and (2) invalid parameter to articleSearch.asp; (3) username and (4) invalid parameter to lostPassword.asp; (5) Username, (6) Password, and (7) invalid… | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Scoop | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Scoop 1.1 RC1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) type and (2) count parameters, and (3) the query string in a story. |