Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

595 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.89%—Jrecms Springbootcms27/9/202317/6/2026
SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by users are not filtered. As a result, special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to execute any SQL statement.
ModificadaCrítica (9.8)94%💥 ExploitCraftcms Craft CMS13/9/202317/6/2026
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
ModificadaAlta (7.2)0.90%—Instantcms Icms213/9/202317/6/2026
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
ModificadaMedia (4.8)0.40%—Instantcms10/9/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.
ModificadaMedia (5.4)0.38%—Instantcms10/9/202317/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaMedia (4.9)0.89%—Instantcms1/9/202317/6/2026
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaMedia (6.1)0.47%—Instantcms31/8/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.
ModificadaBaja (3.5)0.34%—Instantcms31/8/202317/6/2026
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1.
ModificadaMedia (4.8)0.49%—Instantcms31/8/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaMedia (5.4)0.51%—Instantcms31/8/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaMedia (5.4)0.41%—Instantcms31/8/202317/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.
ModificadaMedia (4.7)0.54%—Instantcms31/8/202317/6/2026
Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaMedia (5.4)0.44%—Instantcms31/8/202317/6/2026
Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.
ModificadaCrítica (9.8)2.1%—Pbootcms24/8/202317/6/2026
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
ModificadaAlta (7.2)2.3%—Craftcms Craft CMS23/8/202317/6/2026
Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltrations. Although the vulnerability is exploitable only in the…
ModificadaMedia (4.3)0.43%—Instantcms16/8/202317/6/2026
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaMedia (4.8)0.47%—Instantcms5/8/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaCrítica (9.1)0.93%—Instantcms5/8/202317/6/2026
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaMedia (4.8)0.47%—Instantcms5/8/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
ModificadaMedia (5.4)0.69%—Kiwitcms Kiwi Tcms5/7/202317/6/2026
Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prevent browsers from executing potentially dangerous files when such…
ModificadaMedia (6.1)0.50%—Craftcms Craft CMS20/6/202317/6/2026
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
ModificadaAlta (7.5)0.96%—Otcms14/6/202317/6/2026
A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/read.php?mudi=announContent. The manipulation of the argument url leads to path traversal. The exploit has been disclosed to the public and may be used. The identifier of…
ModificadaMedia (6.5)0.96%—Otcms14/6/202317/6/2026
A vulnerability has been found in OTCMS up to 6.62 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file usersNews_deal.php. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (7.5)0.96%—Otcms14/6/202317/6/2026
A vulnerability, which was classified as problematic, was found in OTCMS up to 6.62. Affected is an unknown function of the file admin/readDeal.php?mudi=readQrCode. The manipulation of the argument img leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-231510 is…
ModificadaCrítica (9.8)0.74%—Otcms14/6/202317/6/2026
A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/read.php?mudi=getSignal. The manipulation of the argument signalUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been…
Orbitaley — Vulnerabilidades