Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.67% | — | Wuzhicms | 5/11/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field. | |
| Modificada | Alta (7.5) | 2.5% | — | Popojicms | 5/11/2018 | 17/6/2026 | An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter. | |
| Modificada | Alta (8.8) | 0.59% | — | Popojicms | 5/11/2018 | 17/6/2026 | An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account. | |
| Modificada | Crítica (9.8) | 0.81% | — | Popojicms | 5/11/2018 | 17/6/2026 | An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be exploited via CSRF. | |
| Modificada | Crítica (9.8) | 2.6% | — | 1234n Minicms | 1/11/2018 | 17/6/2026 | MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. | |
| Modificada | Alta (7.5) | 1.2% | — | 1234n Minicms | 1/11/2018 | 17/6/2026 | MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late. | |
| Modificada | Media (5.3) | 1.5% | — | 1234n Minicms | 1/11/2018 | 17/6/2026 | MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename. | |
| Modificada | Alta (8.8) | 0.65% | — | Wuzhicms | 29/10/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1. | |
| Modificada | Alta (8.8) | 0.65% | — | Wuzhicms | 29/10/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info. | |
| Modificada | Crítica (9.8) | 1.5% | — | Icmsdev Icms | 29/10/2018 | 17/6/2026 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. | |
| Modificada | Media (6.1) | 0.86% | — | Dilicms | 10/10/2018 | 17/6/2026 | XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Dilicms | 10/10/2018 | 17/6/2026 | XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter. | |
| Modificada | Crítica (9.8) | 1.3% | — | Comsenz Duomicms | 9/10/2018 | 17/6/2026 | An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter. | |
| Modificada | Crítica (9.8) | 2.5% | — | Comsenz Duomicms | 9/10/2018 | 17/6/2026 | An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing. | |
| Modificada | Media (6.1) | 2.3% | 💥 Exploit | Wuzhicms Wuzhi CMS | 1/10/2018 | 17/6/2026 | XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter. | |
| Modificada | Media (6.1) | 0.77% | — | Yiqicms Project Yiqicms | 16/9/2018 | 17/6/2026 | An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be bypassed. | |
| Modificada | Media (6.1) | 0.86% | — | 1234n Minicms | 14/9/2018 | 17/6/2026 | MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled. | |
| Modificada | Alta (8.8) | 0.61% | — | Idreamsoft Icms | 2/9/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF. | |
| Modificada | Alta (8.8) | 0.61% | — | Idreamsoft Icms | 2/9/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF. | |
| Modificada | Alta (8.8) | 0.61% | — | Idreamsoft Icms | 2/9/2018 | 17/6/2026 | An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability. | |
| Modificada | Alta (8.8) | 0.52% | — | Damicms | 2/9/2018 | 17/6/2026 | admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password. | |
| Modificada | Alta (7.2) | 2.4% | — | Idreamsoft Icms | 1/9/2018 | 17/6/2026 | idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file. | |
| Modificada | Alta (8.8) | 0.66% | — | Icmsdev Icms | 1/9/2018 | 17/6/2026 | An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is validated, which can be bypassed via an admincp.php substring in this header. | |
| Modificada | Media (6.1) | 0.86% | — | 1234n Minicms | 31/8/2018 | 17/6/2026 | An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request. | |
| Modificada | Crítica (9.8) | 1.2% | — | Damicms | 30/8/2018 | 17/6/2026 | An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses. |