Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.95%—Snewscms Snews4/4/202621/7/2026
Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can upload malicious PHP files through the multipart form-data upload endpoint and execute them by accessing the uploaded…
AnalizadaMedia (6.9)0.16%—Snewscms Snews4/4/202621/7/2026
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credentials without authentication by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting a page containing a hidden form that submits POST requests to the changeup…
ModificadaMedia (6.1)0.70%—Snewscms Snews14/1/202016/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
ModificadaMedia (4.3)1.5%—Antisocialmediallc Antisnews28/9/201116/6/2026
Cross-site scripting (XSS) vulnerability in the Antisnews theme before 1.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
ModificadaAlta (7.5)0.91%—Solucija Snews30/7/201016/6/2026
SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.
ModificadaAlta (7.5)0.97%—Rich Kavanagh Psnews13/7/201016/6/2026
Multiple SQL injection vulnerabilities in PsNews 1.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) ndetail.php and (2) print.php.
ModificadaMedia (4.3)0.89%—Editeurscripts Esnews23/7/200916/6/2026
Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
ModificadaAlta (7.5)1.1%—Typo3 PMK Rssnewsexport Extension3/4/200916/6/2026
SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)0.97%—Bosdev Bosnews23/10/200816/6/2026
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands via the article parameter.
ModificadaMedia (4.3)1.5%—Snews CMS RUS20/3/200816/6/2026
Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.
ModificadaMedia (4.3)1.0%—Bosdev Bosnews5/11/200716/6/2026
Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in a news post.
ModificadaMedia (5)1.2%—Bosdev Bosnews5/11/200716/6/2026
Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account, which allows remote attackers to cause a denial of service (overwritten files) and possibly obtain administrative access.
ModificadaMedia (4.3)1.0%—Snewscms RUS9/10/200716/6/2026
Cross-site scripting (XSS) vulnerability in news_page.php in SnewsCMS Rus 2.1 allows remote attackers to inject arbitrary web script or HTML via the page_id parameter.
ModificadaMedia (6.4)2.4%—Psnews15/7/200716/6/2026
Directory traversal vulnerability in news/show.php in PsNews 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newspath parameter.
ModificadaAlta (10)4.7%—Snews16/1/200716/6/2026
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to perform unauthorized administrative actions, as demonstrated by changing an administrative password via the changeup task, and by uploading PHP code via the imagefile parameter.
ModificadaMedia (4.3)1.3%—Solucija Snews28/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in snews.php in sNews (aka Solucija News) 1.4 allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.
ModificadaAlta (7.5)1.9%—Dsportal Dsnewsletter15/3/200616/6/2026
Multiple SQL injection vulnerabilities in DSNewsletter 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the email parameter to (1) include/sub.php, (2) include/confirm.php, or (3) include/unconfirm.php.
ModificadaAlta (7.5)1.3%—Solucija Snews15/2/200616/6/2026
SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.
ModificadaMedia (4.3)1.8%—Solucija Snews15/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via the comment field.
ModificadaAlta (7.5)1.1%—Solucija Snews27/11/200516/6/2026
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.
ModificadaMedia (4.3)3.6%—Psnews5/9/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PsNews 1.1 allows remote attackers to inject arbitrary web script or HTML via the no parameter.
ModificadaAlta (7.5)32%—Cgiscript Csnews Professional31/12/200216/6/2026
csNewsPro.cgi in CGIScript.net csNews Professional (csNewsPro) allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.
ModificadaMedia (5)3.2%—Cgiscript.net Csnews4/10/200216/6/2026
CGIScript.net csNews.cgi allows remote attackers to obtain database files via a direct URL-encoded request to (1) default%2edb or (2) default%2edb.style, or remote authenticated users to perform administrative actions via (3) a database parameter set to default%2edb.
ModificadaAlta (7.5)7.0%—Cgiscript.net Csnews4/10/200216/6/2026
CGIScript.net csNews.cgi allows remote authenticated users to read arbitrary files, and possibly gain privileges, via the (1) pheader or (2) pfooter parameters in the "Advanced Settings" capability.
ModificadaAlta (7.5)1.4%—Cgiscript.net Csnews4/10/200216/6/2026
CGIScript.net csNews.cgi allows remote authenticated users to execute arbitrary Perl code via terminating quotes and metacharacters in text fields of the "Advanced Settings" capability.