Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.67%—Wuzhicms5/11/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
ModificadaAlta (7.5)2.5%—Popojicms5/11/201817/6/2026
An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter.
ModificadaAlta (8.8)0.59%—Popojicms5/11/201817/6/2026
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.
ModificadaCrítica (9.8)0.81%—Popojicms5/11/201817/6/2026
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be exploited via CSRF.
ModificadaCrítica (9.8)2.6%—1234n Minicms1/11/201817/6/2026
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
ModificadaAlta (7.5)1.2%—1234n Minicms1/11/201817/6/2026
MiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.
ModificadaMedia (5.3)1.5%—1234n Minicms1/11/201817/6/2026
MiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
ModificadaAlta (8.8)0.65%—Wuzhicms29/10/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.
ModificadaAlta (8.8)0.65%—Wuzhicms29/10/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.
ModificadaCrítica (9.8)1.5%—Icmsdev Icms29/10/201817/6/2026
spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.
ModificadaMedia (6.1)0.86%—Dilicms10/10/201817/6/2026
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.
ModificadaMedia (6.1)0.86%—Dilicms10/10/201817/6/2026
XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.
ModificadaCrítica (9.8)1.3%—Comsenz Duomicms9/10/201817/6/2026
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
ModificadaCrítica (9.8)2.5%—Comsenz Duomicms9/10/201817/6/2026
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
ModificadaMedia (6.1)2.3%💥 ExploitWuzhicms Wuzhi CMS1/10/201817/6/2026
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
ModificadaMedia (6.1)0.77%—Yiqicms Project Yiqicms16/9/201817/6/2026
An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be bypassed.
ModificadaMedia (6.1)0.86%—1234n Minicms14/9/201817/6/2026
MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.
ModificadaAlta (8.8)0.61%—Idreamsoft Icms2/9/201817/6/2026
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
ModificadaAlta (8.8)0.61%—Idreamsoft Icms2/9/201817/6/2026
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
ModificadaAlta (8.8)0.61%—Idreamsoft Icms2/9/201817/6/2026
An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
ModificadaAlta (8.8)0.52%—Damicms2/9/201817/6/2026
admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.
ModificadaAlta (7.2)2.4%—Idreamsoft Icms1/9/201817/6/2026
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
ModificadaAlta (8.8)0.66%—Icmsdev Icms1/9/201817/6/2026
An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is validated, which can be bypassed via an admincp.php substring in this header.
ModificadaMedia (6.1)0.86%—1234n Minicms31/8/201817/6/2026
An issue was discovered in MiniCMS 1.10. There is an mc-admin/post.php?tag= XSS vulnerability for a state=delete, state=draft, or state=publish request.
ModificadaCrítica (9.8)1.2%—Damicms30/8/201817/6/2026
An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
Orbitaley — Vulnerabilidades