Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | Kensite CMS Project Kensite CMS | 26/8/2022 | 17/6/2026 | Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at /framework/mod/db/DBMapper.xml. | |
| Modificada | Alta (7.2) | 1.1% | — | Siteservercms Project Siteservercms | 26/8/2022 | 17/6/2026 | SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx. | |
| Modificada | Crítica (9.8) | 15% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | Bluecms 1.6 has SQL injection in line 132 of admin/area.php | |
| Modificada | Crítica (9.8) | 0.88% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | BlueCMS 1.6 has SQL injection in line 55 of admin/model.php | |
| Modificada | Crítica (9.8) | 0.90% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | BlueCMS 1.6 has SQL injection in line 132 of admin/article.php | |
| Modificada | Crítica (9.8) | 1.2% | — | Baijiacms Project Baijiacms | 22/8/2022 | 17/6/2026 | Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. | |
| Modificada | Media (5.4) | 0.60% | — | Company Website CMS Project Company Website CMS | 11/8/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue affects some unknown processing of the file /dashboard/contact. The manipulation of the argument phone leads to cross site scripting. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 1.2% | — | Company Website CMS Project Company Website CMS | 11/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.70% | — | Company Website CMS Project Company Website CMS | 11/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this… | |
| Modificada | Crítica (9.8) | 0.70% | — | Company Website CMS Project Company Website CMS | 11/8/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-206022 is the… | |
| Modificada | Crítica (9.8) | 0.70% | — | Company Website CMS Project Company Website CMS | 11/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882… | |
| Modificada | Crítica (9.8) | 0.70% | — | Company Website CMS Project Company Website CMS | 11/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the… | |
| Modificada | Crítica (9.8) | 1.1% | — | Ucms Project Ucms | 10/8/2022 | 17/6/2026 | UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. | |
| Modificada | Media (6.1) | 0.46% | — | Company Website CMS Project Company Website CMS | 9/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this… | |
| Modificada | Media (6.5) | 0.63% | — | Company Website/cms Project Company Website/cms | 8/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 0.85% | — | Company Website CMS Project Company Website CMS | 6/8/2022 | 17/6/2026 | A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205817 was… | |
| Modificada | Crítica (9.8) | 1.0% | — | Atoms183 CMS Project Atoms183 CMS | 7/7/2022 | 17/6/2026 | SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php. | |
| Modificada | Alta (7.2) | 0.93% | — | Hongcms Project Hongcms | 1/7/2022 | 17/6/2026 | An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell. | |
| Modificada | Alta (7.2) | 0.93% | — | Hongcms Project Hongcms | 1/7/2022 | 17/6/2026 | An issue in the languages config file of HongCMS v3.0 allows attackers to getshell. | |
| Modificada | Media (4.8) | 0.52% | — | Lightcms Project Lightcms | 27/6/2022 | 9/7/2026 | A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file. | |
| Modificada | Media (5.4) | 0.43% | — | Unioncms Project Unioncms | 21/6/2022 | 9/7/2026 | Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings. | |
| Modificada | Alta (8.8) | 1.5% | — | Victor CMS Project Victor CMS | 16/6/2022 | 17/6/2026 | Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Kkcms Project Kkcms | 15/6/2022 | 17/6/2026 | kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php. | |
| Modificada | Media (6.1) | 0.57% | — | Ofcms Project Ofcms | 2/6/2022 | 17/6/2026 | OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. | |
| Modificada | Alta (8.8) | 1.3% | — | Tpcms Project Tpcms | 2/6/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file. |