Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.0%—Kensite CMS Project Kensite CMS26/8/202217/6/2026
Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at /framework/mod/db/DBMapper.xml.
ModificadaAlta (7.2)1.1%—Siteservercms Project Siteservercms26/8/202217/6/2026
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
ModificadaCrítica (9.8)15%—Bluecms Project Bluecms23/8/202217/6/2026
Bluecms 1.6 has SQL injection in line 132 of admin/area.php
ModificadaCrítica (9.8)0.88%—Bluecms Project Bluecms23/8/202217/6/2026
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php
ModificadaCrítica (9.8)0.90%—Bluecms Project Bluecms23/8/202217/6/2026
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php
ModificadaCrítica (9.8)1.2%—Baijiacms Project Baijiacms22/8/202217/6/2026
Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.
ModificadaMedia (5.4)0.60%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue affects some unknown processing of the file /dashboard/contact. The manipulation of the argument phone leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)1.2%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-206022 is the…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the…
ModificadaCrítica (9.8)1.1%—Ucms Project Ucms10/8/202217/6/2026
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
ModificadaMedia (6.1)0.46%—Company Website CMS Project Company Website CMS9/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this…
ModificadaMedia (6.5)0.63%—Company Website/cms Project Company Website/cms8/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been…
ModificadaAlta (8.8)0.85%—Company Website CMS Project Company Website CMS6/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205817 was…
ModificadaCrítica (9.8)1.0%—Atoms183 CMS Project Atoms183 CMS7/7/202217/6/2026
SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.
ModificadaAlta (7.2)0.93%—Hongcms Project Hongcms1/7/202217/6/2026
An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.
ModificadaAlta (7.2)0.93%—Hongcms Project Hongcms1/7/202217/6/2026
An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.
ModificadaMedia (4.8)0.52%—Lightcms Project Lightcms27/6/20229/7/2026
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.
ModificadaMedia (5.4)0.43%—Unioncms Project Unioncms21/6/20229/7/2026
Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.
ModificadaAlta (8.8)1.5%—Victor CMS Project Victor CMS16/6/202217/6/2026
Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.
ModificadaCrítica (9.8)1.1%—Kkcms Project Kkcms15/6/202217/6/2026
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.
ModificadaMedia (6.1)0.57%—Ofcms Project Ofcms2/6/202217/6/2026
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.
ModificadaAlta (8.8)1.3%—Tpcms Project Tpcms2/6/202217/6/2026
An arbitrary file upload vulnerability in the Add File function of TPCMS v3.2 allows attackers to execute arbitrary code via a crafted PHP file.
Orbitaley — Vulnerabilidades