Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)2.2%—Damicms30/8/201817/6/2026
An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl/default/head.html file.
ModificadaBaja (2.7)1.2%—Damicms30/8/201817/6/2026
An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI.
ModificadaMedia (6.1)0.86%—1234n Minicms30/8/201817/6/2026
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter.
ModificadaMedia (6.1)0.88%—1234n Minicms27/8/201817/6/2026
An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
ModificadaAlta (7.5)1.5%—Icmsdev Icms27/8/201817/6/2026
An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP addresses, as demonstrated by 127.0.0.1 in an A record. NOTE: this vulnerability exists because of an incomplete fix for…
ModificadaAlta (8.8)2.5%💥 ExploitDamicms25/8/201817/6/2026
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.
ModificadaMedia (6.1)2.2%💥 Exploit1234n Minicms20/8/201817/6/2026
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.
ModificadaAlta (7.5)1.5%—Icmsdev Icms2/8/201817/6/2026
An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not block private and reserved IP addresses such as 10.0.0.0/8. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-14514.
ModificadaCrítica (9.8)1.6%—Icmsdev Icms23/7/201817/6/2026
An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact.
ModificadaMedia (6.1)1.1%—Wuzhicms23/7/201817/6/2026
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload…
ModificadaAlta (7.2)1.8%—Wuzhicms20/7/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection.
ModificadaMedia (6.1)0.83%—Icmsdev Icms20/7/201817/6/2026
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
ModificadaMedia (6.1)1.0%—Idreamsoft Icms10/7/201817/6/2026
An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.
ModificadaAlta (8.8)1.1%—Damicms5/7/201817/6/2026
DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.
ModificadaCrítica (9.8)1.5%—Icmsdev Icms15/6/201817/6/2026
spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php.
ModificadaCrítica (9.8)1.5%—Wuzhicms5/6/201817/6/2026
WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
ModificadaMedia (5.4)0.66%—Wuzhicms29/5/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring.
ModificadaCrítica (9.8)1.5%—Wuzhicms29/5/201817/6/2026
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
ModificadaAlta (8.8)0.64%—Wuzhicms26/5/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.
ModificadaMedia (4.8)0.65%—Dilicms26/4/201817/6/2026
An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php.
ModificadaBaja (2.7)0.93%—1234n Minicms26/4/201817/6/2026
mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.
ModificadaBaja (2.7)1.3%—1234n Minicms26/4/201817/6/2026
mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.
ModificadaMedia (4.8)0.65%—Wuzhicms26/4/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.
ModificadaMedia (4.8)0.65%—Wuzhicms25/4/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.
ModificadaMedia (4.8)0.65%—Wuzhicms25/4/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section.