Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.25% | — | Tpmecms | 30/8/2024 | 17/6/2026 | TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields. | |
| Analizada | Alta (7.2) | 0.86% | — | Dedecms | 23/8/2024 | 17/6/2026 | DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath. | |
| Analizada | Media (5.1) | 0.53% | — | Tpmecms | 17/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in xiaohe4966 TpMeCMS 1.3.3.2. Affected is an unknown function of the file /h.php/general/config?ref=addtabs of the component Basic Configuration Handler. The manipulation of the argument Site Name/Beian/Contact address/copyright/technical support leads… | |
| Modificada | Media (4.6) | 0.40% | — | Concretecms Concrete CMS | 12/8/2024 | 17/6/2026 | Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue administrator could inject malicious code. The Concrete CMS security team gave this vulnerability a CVSS 4.0 Score of 4.6 with vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N.… | |
| Modificada | Media (5.1) | 0.49% | — | Concretecms Concrete CMS | 12/8/2024 | 17/6/2026 | Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is stored and later embedded into responses. A rogue administrator could inject malicious code into fields due to insufficient input validation. The Concrete CMS security team gave this vulnerability a… | |
| Modificada | Media (4.6) | 0.44% | — | Concretecms Concrete CMS | 8/8/2024 | 17/6/2026 | Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVSS v4.0 rank of 4.6 with vector… | |
| Modificada | Media (4.6) | 0.30% | — | Concretecms Concrete CMS | 1/8/2024 | 17/6/2026 | Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board instance functionality. The Name input field does not check the input sufficiently letting a rogue administrator have the capability to inject malicious JavaScript code. The Concrete CMS security team… | |
| Modificada | Media (5.1) | 0.67% | — | Dedecms | 21/7/2024 | 17/6/2026 | A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated… | |
| Analizada | Media (5.3) | 0.34% | — | Jrecms Springbootcms | 7/7/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unknown function of the file /guestbook of the component Guestbook Handler. The manipulation of the argument Content leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Media (5.4) | 0.93% | 💥 Exploit | Coderberg Residencecms | 2/7/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts as a stored XSS payload. | |
| Analizada | Crítica (9.8) | 0.73% | — | Dedecms | 28/5/2024 | 17/6/2026 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Analizada | Crítica (9.8) | 0.47% | — | Dedecms | 23/5/2024 | 17/6/2026 | There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS | |
| Analizada | Media (5.5) | 0.28% | — | Dedecms | 17/5/2024 | 17/6/2026 | DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php. | |
| Analizada | Media (5.3) | 1.1% | — | Dedecms | 14/5/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in DedeCMS 5.7.114. This affects an unknown part of the file /sys_verifies.php?action=view. The manipulation of the argument filename with the input ../../../../../etc/passwd leads to path traversal: '../filedir'. It is possible to initiate the attack remotely.… | |
| Analizada | Media (6.5) | 0.82% | — | Dedecms | 14/5/2024 | 17/6/2026 | An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php. | |
| Analizada | Media (4.3) | 0.42% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. Affected is an unknown function of the file /src/dede/sys_safe.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (4.3) | 0.43% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. This issue affects some unknown processing of the file /src/dede/sys_multiserv.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (4.3) | 0.43% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/sys_group_edit.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263314 is… | |
| Analizada | Media (4.3) | 0.43% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/sys_group_add.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (4.3) | 0.42% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/sys_info.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (4.3) | 0.42% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (4.3) | 0.42% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (4.3) | 0.42% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability was found in DedeCMS 5.7 and classified as problematic. This issue affects some unknown processing of the file /src/dede/tpl.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Analizada | Media (4.3) | 0.42% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/shops_delivery.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Media (4.3) | 0.43% | — | Dedecms | 7/5/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/member_type.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… |