Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.89% | — | Jrecms Springbootcms | 27/9/2023 | 17/6/2026 | SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by users are not filtered. As a result, special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to execute any SQL statement. | |
| Modificada | Crítica (9.8) | 94% | 💥 Exploit | Craftcms Craft CMS | 13/9/2023 | 17/6/2026 | Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15. | |
| Modificada | Alta (7.2) | 0.90% | — | Instantcms Icms2 | 13/9/2023 | 17/6/2026 | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. | |
| Modificada | Media (4.8) | 0.40% | — | Instantcms | 10/9/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git. | |
| Modificada | Media (5.4) | 0.38% | — | Instantcms | 10/9/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (4.9) | 0.89% | — | Instantcms | 1/9/2023 | 17/6/2026 | External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (6.1) | 0.47% | — | Instantcms | 31/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1. | |
| Modificada | Baja (3.5) | 0.34% | — | Instantcms | 31/8/2023 | 17/6/2026 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository instantsoft/icms2 prior to 2.16.1. | |
| Modificada | Media (4.8) | 0.49% | — | Instantcms | 31/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (5.4) | 0.51% | — | Instantcms | 31/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (5.4) | 0.41% | — | Instantcms | 31/8/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1. | |
| Modificada | Media (4.7) | 0.54% | — | Instantcms | 31/8/2023 | 17/6/2026 | Improper Access Control in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (5.4) | 0.44% | — | Instantcms | 31/8/2023 | 17/6/2026 | Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1. | |
| Modificada | Crítica (9.8) | 2.1% | — | Pbootcms | 24/8/2023 | 17/6/2026 | PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function. | |
| Modificada | Alta (7.2) | 2.3% | — | Craftcms Craft CMS | 23/8/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltrations. Although the vulnerability is exploitable only in the… | |
| Modificada | Media (4.3) | 0.43% | — | Instantcms | 16/8/2023 | 17/6/2026 | Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (4.8) | 0.47% | — | Instantcms | 5/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Crítica (9.1) | 0.93% | — | Instantcms | 5/8/2023 | 17/6/2026 | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (4.8) | 0.47% | — | Instantcms | 5/8/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1-git. | |
| Modificada | Media (5.4) | 0.69% | — | Kiwitcms Kiwi Tcms | 5/7/2023 | 17/6/2026 | Kiwi TCMS, an open source test management system allows users to upload attachments to test plans, test cases, etc. Versions of Kiwi TCMS prior to 12.5 had introduced changes which were meant to serve all uploaded files as plain text in order to prevent browsers from executing potentially dangerous files when such… | |
| Modificada | Media (6.1) | 0.50% | — | Craftcms Craft CMS | 20/6/2023 | 17/6/2026 | Craft CMS through 4.4.9 is vulnerable to HTML Injection. | |
| Modificada | Alta (7.5) | 0.96% | — | Otcms | 14/6/2023 | 17/6/2026 | A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/read.php?mudi=announContent. The manipulation of the argument url leads to path traversal. The exploit has been disclosed to the public and may be used. The identifier of… | |
| Modificada | Media (6.5) | 0.96% | — | Otcms | 14/6/2023 | 17/6/2026 | A vulnerability has been found in OTCMS up to 6.62 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file usersNews_deal.php. The manipulation of the argument file leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (7.5) | 0.96% | — | Otcms | 14/6/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in OTCMS up to 6.62. Affected is an unknown function of the file admin/readDeal.php?mudi=readQrCode. The manipulation of the argument img leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. VDB-231510 is… | |
| Modificada | Crítica (9.8) | 0.74% | — | Otcms | 14/6/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/read.php?mudi=getSignal. The manipulation of the argument signalUrl leads to server-side request forgery. The attack may be initiated remotely. The exploit has been… |