Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.37% | — | Pb-cms Project Pb-cms | 8/12/2022 | 17/6/2026 | A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability is the function IpUtil.getIpAddr. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Alta (8) | 0.47% | — | Duxcms Project Duxcms | 8/12/2022 | 17/6/2026 | A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability… | |
| Modificada | Media (5.4) | 0.40% | — | Duxcms Project Duxcms | 8/12/2022 | 17/6/2026 | A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of the file admin.php&r=article/AdminContent/edit of the component Article Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack… | |
| Modificada | Crítica (9.8) | 1.6% | — | Ayacms Project Ayacms | 7/12/2022 | 17/6/2026 | AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE). | |
| Modificada | Alta (8.8) | 0.82% | — | Ayacms Project Ayacms | 6/12/2022 | 17/6/2026 | AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. | |
| Modificada | Alta (7.5) | 0.79% | — | Aerocms Project Aerocms | 29/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information. | |
| Modificada | Media (4.9) | 0.86% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information. | |
| Modificada | Media (4.9) | 0.83% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information. | |
| Modificada | Media (4.9) | 0.78% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information. | |
| Modificada | Alta (7.5) | 0.81% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information. | |
| Modificada | Alta (7.5) | 0.81% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information. | |
| Modificada | Crítica (9.8) | 0.83% | — | Dreamer CMS Project Dreamer CMS | 17/11/2022 | 17/6/2026 | Dreamer CMS 4.0.01 is vulnerable to SQL Injection. | |
| Modificada | Media (5.4) | 0.38% | — | Foru CMS Project Foru CMS | 11/11/2022 | 17/6/2026 | A vulnerability was found in ForU CMS. It has been classified as problematic. Affected is an unknown function of the file cms_chip.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.99% | — | Ayacms Project Ayacms | 10/11/2022 | 17/6/2026 | AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (6.6) | 1.1% | — | Lin-cms Project Lin-cms | 9/11/2022 | 17/6/2026 | An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator. | |
| Modificada | Crítica (9.8) | 0.89% | — | Mkcms Project Mkcms | 3/11/2022 | 17/6/2026 | MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter. | |
| Modificada | Crítica (9.8) | 0.89% | — | Mkcms Project Mkcms | 3/11/2022 | 17/6/2026 | MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter. | |
| Modificada | Crítica (9.8) | 0.89% | — | Mkcms Project Mkcms | 3/11/2022 | 17/6/2026 | MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter. | |
| Modificada | Alta (8.8) | 0.87% | — | Ucms Project Ucms | 14/10/2022 | 17/6/2026 | There is a file inclusion vulnerability in the template management module in UCMS 1.6 | |
| Modificada | Alta (8.8) | 1.3% | — | Baijiacms Project Baijiacms | 20/9/2022 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the url parameter. | |
| Modificada | Media (6.1) | 0.57% | — | Ucms Project Ucms | 19/9/2022 | 17/6/2026 | UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page. | |
| Modificada | Alta (8.8) | 1.2% | — | Aerocms Project Aerocms | 13/9/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Crítica (9.8) | 1.3% | — | Ucms Project Ucms | 12/9/2022 | 17/6/2026 | UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning. | |
| Modificada | Media (6.5) | 3.5% | 💥 Exploit | Shirne CMS Project Shirne CMS | 9/9/2022 | 17/6/2026 | An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/controller.php | |
| Modificada | Media (6.5) | 2.6% | 💥 Exploit | Aerocms Project Aerocms | 31/8/2022 | 17/6/2026 | AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. |