Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.37%—Pb-cms Project Pb-cms8/12/202217/6/2026
A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability is the function IpUtil.getIpAddr. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaAlta (8)0.47%—Duxcms Project Duxcms8/12/202217/6/2026
A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability…
ModificadaMedia (5.4)0.40%—Duxcms Project Duxcms8/12/202217/6/2026
A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of the file admin.php&r=article/AdminContent/edit of the component Article Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack…
ModificadaCrítica (9.8)1.6%—Ayacms Project Ayacms7/12/202217/6/2026
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
ModificadaAlta (8.8)0.82%—Ayacms Project Ayacms6/12/202217/6/2026
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.
ModificadaAlta (7.5)0.79%—Aerocms Project Aerocms29/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.
ModificadaMedia (4.9)0.86%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.
ModificadaMedia (4.9)0.83%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
ModificadaMedia (4.9)0.78%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
ModificadaAlta (7.5)0.81%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.
ModificadaAlta (7.5)0.81%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
ModificadaCrítica (9.8)0.83%—Dreamer CMS Project Dreamer CMS17/11/202217/6/2026
Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
ModificadaMedia (5.4)0.38%—Foru CMS Project Foru CMS11/11/202217/6/2026
A vulnerability was found in ForU CMS. It has been classified as problematic. Affected is an unknown function of the file cms_chip.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.99%—Ayacms Project Ayacms10/11/202217/6/2026
AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (6.6)1.1%—Lin-cms Project Lin-cms9/11/202217/6/2026
An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.
ModificadaCrítica (9.8)0.89%—Mkcms Project Mkcms3/11/202217/6/2026
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
ModificadaCrítica (9.8)0.89%—Mkcms Project Mkcms3/11/202217/6/2026
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
ModificadaCrítica (9.8)0.89%—Mkcms Project Mkcms3/11/202217/6/2026
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
ModificadaAlta (8.8)0.87%—Ucms Project Ucms14/10/202217/6/2026
There is a file inclusion vulnerability in the template management module in UCMS 1.6
ModificadaAlta (8.8)1.3%—Baijiacms Project Baijiacms20/9/202217/6/2026
A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the url parameter.
ModificadaMedia (6.1)0.57%—Ucms Project Ucms19/9/202217/6/2026
UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.
ModificadaAlta (8.8)1.2%—Aerocms Project Aerocms13/9/202217/6/2026
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaCrítica (9.8)1.3%—Ucms Project Ucms12/9/202217/6/2026
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
ModificadaMedia (6.5)3.5%💥 ExploitShirne CMS Project Shirne CMS9/9/202217/6/2026
An issue was discovered in Shirne CMS 1.2.0. There is a Path Traversal vulnerability which could cause arbitrary file read via /static/ueditor/php/controller.php
ModificadaMedia (6.5)2.6%💥 ExploitAerocms Project Aerocms31/8/202217/6/2026
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
Orbitaley — Vulnerabilidades