Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 2.2% | — | Damicms | 30/8/2018 | 17/6/2026 | An issue was discovered in damiCMS V6.0.1. Remote code execution can occur via PHP code in a multipart/form-data POST to the admin.php?s=/Tpl/Update.html URI. For example, this can update the Web/Tpl/default/head.html file. | |
| Modificada | Baja (2.7) | 1.2% | — | Damicms | 30/8/2018 | 17/6/2026 | An issue was discovered in damiCMS V6.0.1. There is Directory Traversal via '|' characters in the s parameter to admin.php, as demonstrated by an admin.php?s=Tpl/Add/id/c:|windows|win.ini URI. | |
| Modificada | Media (6.1) | 0.86% | — | 1234n Minicms | 30/8/2018 | 17/6/2026 | MiniCMS V1.10 has XSS via the mc-admin/post-edit.php tags parameter. | |
| Modificada | Media (6.1) | 0.88% | — | 1234n Minicms | 27/8/2018 | 17/6/2026 | An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability. | |
| Modificada | Alta (7.5) | 1.5% | — | Icmsdev Icms | 27/8/2018 | 17/6/2026 | An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP addresses, as demonstrated by 127.0.0.1 in an A record. NOTE: this vulnerability exists because of an incomplete fix for… | |
| Modificada | Alta (8.8) | 2.5% | 💥 Exploit | Damicms | 25/8/2018 | 17/6/2026 | An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit. | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | 1234n Minicms | 20/8/2018 | 17/6/2026 | MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection. | |
| Modificada | Alta (7.5) | 1.5% | — | Icmsdev Icms | 2/8/2018 | 17/6/2026 | An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not block private and reserved IP addresses such as 10.0.0.0/8. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-14514. | |
| Modificada | Crítica (9.8) | 1.6% | — | Icmsdev Icms | 23/7/2018 | 17/6/2026 | An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact. | |
| Modificada | Media (6.1) | 1.1% | — | Wuzhicms | 23/7/2018 | 17/6/2026 | An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload… | |
| Modificada | Alta (7.2) | 1.8% | — | Wuzhicms | 20/7/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0. The vulnerable file is coreframe/app/order/admin/goods.php. The $keywords parameter is taken directly into execution without any filtering, leading to SQL injection. | |
| Modificada | Media (6.1) | 0.83% | — | Icmsdev Icms | 20/7/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen. | |
| Modificada | Media (6.1) | 1.0% | — | Idreamsoft Icms | 10/7/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism. | |
| Modificada | Alta (8.8) | 1.1% | — | Damicms | 5/7/2018 | 17/6/2026 | DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account. | |
| Modificada | Crítica (9.8) | 1.5% | — | Icmsdev Icms | 15/6/2018 | 17/6/2026 | spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Wuzhicms | 5/6/2018 | 17/6/2026 | WUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded. | |
| Modificada | Media (5.4) | 0.66% | — | Wuzhicms | 29/5/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq_10]= substring. | |
| Modificada | Crítica (9.8) | 1.5% | — | Wuzhicms | 29/5/2018 | 17/6/2026 | WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI. | |
| Modificada | Alta (8.8) | 0.64% | — | Wuzhicms | 26/5/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add. | |
| Modificada | Media (4.8) | 0.65% | — | Dilicms | 26/4/2018 | 17/6/2026 | An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php. | |
| Modificada | Baja (2.7) | 0.93% | — | 1234n Minicms | 26/4/2018 | 17/6/2026 | mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field. | |
| Modificada | Baja (2.7) | 1.3% | — | 1234n Minicms | 26/4/2018 | 17/6/2026 | mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article. | |
| Modificada | Media (4.8) | 0.65% | — | Wuzhicms | 26/4/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI. | |
| Modificada | Media (4.8) | 0.65% | — | Wuzhicms | 25/4/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement. | |
| Modificada | Media (4.8) | 0.65% | — | Wuzhicms | 25/4/2018 | 17/6/2026 | An issue was discovered in WUZHI CMS 4.1.0. The content-management feature has Stored XSS via the title or content section. |