Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.78% | — | Ltcms | 13/8/2024 | 17/6/2026 | A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This vulnerability affects the function download of the file /api/test/download of the component API Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The… | |
| Analizada | Media (5.3) | 0.43% | — | Xjd2020 Fastcms | 13/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in FastCMS up to 0.1.5. Affected is an unknown function of the component New Article Category Page. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.40% | — | Boltcms Bolt | 31/7/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase Creation Handler. The manipulation of the argument title/textarea leads to cross site scripting. It is possible to launch the attack remotely.… | |
| Analizada | Media (5.3) | 0.39% | — | Boltcms Bolt | 31/7/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issue affects some unknown processing of the file /preview/page of the component Entry Preview Handler. The manipulation of the argument body leads to cross site scripting. The attack may be initiated… | |
| Modificada | Media (6.1) | 0.25% | — | Dotcms | 25/7/2024 | 17/6/2026 | The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested to see the vulnerability may spin up a… | |
| Modificada | Alta (7.5) | 0.46% | — | Craftcms Craft CMS | 25/7/2024 | 17/6/2026 | Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in… | |
| Analizada | Media (5.3) | 0.34% | — | Jrecms Springbootcms | 7/7/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unknown function of the file /guestbook of the component Guestbook Handler. The manipulation of the argument Content leads to cross site scripting. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 53% | 💥 Exploit | Craftcms Craft CMS | 25/6/2024 | 17/6/2026 | Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint. | |
| Modificada | Media (6.3) | 0.60% | — | Spa-cartcms | 18/6/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username Handler. The manipulation of the argument email leads to observable behavioral discrepancy. It is possible to launch the attack remotely. The complexity… | |
| Modificada | Media (6.9) | 0.54% | — | Spa-cartcms | 18/6/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unknown processing of the file /checkout of the component Checkout Page. The manipulation of the argument quantity with the input -10 leads to enforcement of behavioral workflow. The attack may be… | |
| Analizada | Media (5.1) | 0.32% | — | Xjd2020 Fastcms | 24/5/2024 | 17/6/2026 | A vulnerability was found in FastCMS up to 0.1.5 and classified as problematic. Affected by this issue is some unknown functionality of the component New Article Tab. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (5.4) | 0.40% | — | Instantcms | 5/4/2024 | 17/6/2026 | InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2 when being redirected after modifying one's own user profile. An attacker could trick a victim into visiting their web application, thinking they are still present on the ICMS2… | |
| Analizada | Alta (7.2) | 0.85% | — | Instantcms | 4/4/2024 | 17/6/2026 | InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2 in which an attacker with administrative privileges can cause the application to execute unauthorized SQL code. The vulnerability exists in index_chart_data action, which receives an input from user… | |
| Analizada | Media (4.5) | 0.50% | — | Dotcms | 1/4/2024 | 17/6/2026 | System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security… | |
| Analizada | Media (4.5) | 0.47% | — | Dotcms | 1/4/2024 | 17/6/2026 | In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access to the System Maintenance → Tools portlet.… | |
| Analizada | Alta (8.1) | 0.60% | — | Ctcms Project Ctcms | 27/2/2024 | 17/6/2026 | A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of the file ctcms/apps/controllers/admin/Upsys.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation… | |
| Modificada | Alta (7.5) | 1.1% | — | Craftcms Craft CMS | 30/1/2024 | 17/6/2026 | An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volume selected. NOTE: this is not a report about code provided by the… | |
| Modificada | Media (5.4) | 0.38% | — | Craftcms Craft CMS | 30/1/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation. | |
| Modificada | Media (6.1) | 0.51% | — | Pbootcms | 29/1/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.4) | 0.33% | — | Lightcms Project Lightcms | 29/1/2024 | 17/6/2026 | LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field. | |
| Modificada | Alta (7.5) | 0.61% | — | Pbootcms | 4/1/2024 | 17/6/2026 | Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform. | |
| Modificada | Alta (8.8) | 0.59% | — | Craftcms Craft CMS | 3/1/2024 | 17/6/2026 | Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at… | |
| Modificada | Alta (7.2) | 0.58% | — | Otcms | 13/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in OTCMS 7.01. Affected is an unknown function of the file /admin/ind_backstage.php. The manipulation of the argument sqlContent leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (6.1) | 0.36% | — | Dotcms | 17/10/2023 | 17/6/2026 | In dotCMS, versions mentioned, a flaw in the NormalizationFilter does not strip double slashes (//) from URLs, potentially enabling bypasses for XSS and access controls. An example affected URL is https://demo.dotcms.com//html/portlet/ext/files/edit_text_inc.jsp , which should return a 404 response but didn't. The… | |
| Modificada | Media (5.4) | 0.40% | — | Jrecms Springbootcms | 27/9/2023 | 17/6/2026 | SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comments, these malicious codes embedded in the HTML will be executed, and the user's browser will be controlled by the attacker, so as to achieve the special purpose of the attacker, such as cookie theft |