Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.95% | — | Snewscms Snews | 4/4/2026 | 21/7/2026 | Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded… | |
| Analizada | Media (6.9) | 0.16% | — | Snewscms Snews | 4/4/2026 | 21/7/2026 | Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup… | |
| Modificada | Media (6.1) | 0.70% | — | Snewscms Snews | 14/1/2020 | 16/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71. | |
| Modificada | Media (4.3) | 1.5% | — | Antisocialmediallc Antisnews | 28/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Antisnews theme before 1.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | |
| Modificada | Alta (7.5) | 0.91% | — | Solucija Snews | 30/7/2010 | 16/6/2026 | SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Rich Kavanagh Psnews | 13/7/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in PsNews 1.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) ndetail.php and (2) print.php. | |
| Modificada | Media (4.3) | 0.89% | — | Editeurscripts Esnews | 23/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Typo3 PMK Rssnewsexport Extension | 3/4/2009 | 16/6/2026 | SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.97% | — | Bosdev Bosnews | 23/10/2008 | 16/6/2026 | SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Snews CMS RUS | 20/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Bosdev Bosnews | 5/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in a news post. | |
| Modificada | Media (5) | 1.2% | — | Bosdev Bosnews | 5/11/2007 | 16/6/2026 | Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers to cause a denial of service (overwritten files) and possibly obtain administrative access. | |
| Modificada | Media (4.3) | 1.0% | — | Snewscms RUS | 9/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter. | |
| Modificada | Media (6.4) | 2.4% | — | Psnews | 15/7/2007 | 16/6/2026 | Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newspath parameter. | |
| Modificada | Alta (10) | 4.7% | — | Snews | 16/1/2007 | 16/6/2026 | snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Solucija Snews | 28/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Dsportal Dsnewsletter | 15/3/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Solucija Snews | 15/2/2006 | 16/6/2026 | SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters. | |
| Modificada | Media (4.3) | 1.8% | — | Solucija Snews | 15/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field. | |
| Modificada | Alta (7.5) | 1.1% | — | Solucija Snews | 27/11/2005 | 16/6/2026 | SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php. | |
| Modificada | Media (4.3) | 3.6% | — | Psnews | 5/9/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter. | |
| Modificada | Alta (7.5) | 32% | — | Cgiscript Csnews Professional | 31/12/2002 | 16/6/2026 | csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. | |
| Modificada | Media (5) | 3.2% | — | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb. | |
| Modificada | Alta (7.5) | 7.0% | — | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability. | |
| Modificada | Alta (7.5) | 1.4% | — | Cgiscript.net Csnews | 4/10/2002 | 16/6/2026 | CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability. |