Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.98% | — | Gxcms Project Gxcms | 17/5/2022 | 17/6/2026 | GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content and then rename to PHP suffix file, after calling PHP file can control the server. | |
| Modificada | Alta (8.8) | 1.6% | — | Waimairencms Project Waimairencms | 11/5/2022 | 17/6/2026 | An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1. | |
| Modificada | Crítica (9.8) | 22% | — | Waimairencms Project Waimairencms | 11/5/2022 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability exists in waimairen 9.1 via wx.php | |
| Modificada | Crítica (9.8) | 1.1% | — | Bluecms Project Bluecms | 3/5/2022 | 17/6/2026 | Bluecms 1.6 has a SQL injection vulnerability at cooike. | |
| Modificada | Alta (7.5) | 1.6% | — | Victor CMS Project Victor CMS | 28/4/2022 | 17/6/2026 | SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php. | |
| Modificada | Crítica (9.1) | 1.1% | — | Dscms Project Dscms | 28/4/2022 | 17/6/2026 | DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php. | |
| Modificada | Alta (8.1) | 1.1% | — | Dhcms Project Dhcms | 26/4/2022 | 17/6/2026 | dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del. | |
| Modificada | Alta (8.8) | 1.0% | — | Ed01-cms Project Ed01-cms | 26/4/2022 | 17/6/2026 | ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1. | |
| Modificada | Crítica (9.8) | 0.94% | — | Ed01-cms Project Ed01-cms | 26/4/2022 | 17/6/2026 | ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php. | |
| Modificada | Alta (8.1) | 1.1% | — | Hongcms Project Hongcms | 26/4/2022 | 17/6/2026 | HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. | |
| Modificada | Media (5.4) | 0.61% | — | Zcms Project Zcms | 26/4/2022 | 17/6/2026 | ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add. | |
| Modificada | Crítica (9.8) | 1.6% | — | Zcms Project Zcms | 26/4/2022 | 17/6/2026 | ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config. | |
| Modificada | Media (5.4) | 0.49% | — | Gallerycms Project Gallerycms | 25/4/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in /index.php/album/add of GalleryCMS v2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the album_name parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jfinalcms Project Jfinalcms | 22/4/2022 | 17/6/2026 | JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. | |
| Modificada | Alta (7.5) | 1.5% | — | Ucms Project Ucms | 21/4/2022 | 17/6/2026 | UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. | |
| Modificada | Crítica (9.1) | 0.99% | — | Ucms Project Ucms | 21/4/2022 | 17/6/2026 | UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. | |
| Modificada | Alta (8.8) | 1.7% | — | Ucms Project Ucms | 21/4/2022 | 17/6/2026 | An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (8.8) | 20% | — | Victor CMS Project Victor CMS | 21/4/2022 | 17/6/2026 | Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin. | |
| Modificada | Media (5.4) | 0.44% | — | Ofcms Project Ofcms | 10/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box. | |
| Modificada | Media (5.4) | 0.47% | — | Ofcms Project Ofcms | 10/4/2022 | 17/6/2026 | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information. | |
| Modificada | Media (6.1) | 1.5% | — | Aerocms Project Aerocms | 8/4/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field. | |
| Modificada | Media (4.8) | 1.1% | — | Aerocms Project Aerocms | 8/4/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field. | |
| Modificada | Alta (7.2) | 2.7% | — | Aerocms Project Aerocms | 8/4/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Crítica (9.8) | 1.4% | — | Php-cms Project Php-cms | 6/4/2022 | 17/6/2026 | PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Horizontcms Project Horizontcms | 5/4/2022 | 17/6/2026 | File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media Files upload functionality. The original file upload vulnerability (CVE-2020-27387) was remediated by restricting the PHP extensions; however, we confirmed that the filter was bypassed via uploading… |