Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.93% | — | Otcms | 14/6/2023 | 17/6/2026 | A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input admin leads to use of hard-coded password. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability… | |
| Modificada | Alta (7.2) | 2.2% | — | Craftcms Craft CMS | 13/6/2023 | 17/6/2026 | CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig… | |
| Modificada | Media (5.4) | 0.87% | 💥 PoC | Kiwitcms Kiwi Tcms | 6/6/2023 | 17/6/2026 | Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files from being uploaded and… | |
| Modificada | Media (6.1) | 0.65% | — | Craftcms Craft CMS | 27/5/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6. | |
| Modificada | Media (5.4) | 0.43% | — | Kiwitcms Kiwi Tcms | 27/5/2023 | 17/6/2026 | Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS allows users to upload attachments to test plans, test cases, etc. Earlier versions of Kiwi TCMS had introduced upload validators in order to prevent potentially dangerous files from being uploaded. The upload… | |
| Modificada | Media (5.4) | 0.65% | — | Craftcms Craft CMS | 26/5/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7. | |
| Modificada | Media (4.8) | 0.62% | — | Craftcms Craft CMSCraftercms | 26/5/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6. | |
| Modificada | Media (5.4) | 0.68% | — | Craftcms Craft CMS | 26/5/2023 | 17/6/2026 | Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6. | |
| Modificada | Media (5.4) | 0.44% | — | Craftcms Craft CMS | 26/5/2023 | 17/6/2026 | A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively. | |
| Modificada | Alta (7.2) | 1.8% | — | Craftcms Craft CMS | 19/5/2023 | 17/6/2026 | Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateExist() -> resolveTemplate() -> _resolveTemplateInternal() -> _resolveTemplate()… | |
| Modificada | Alta (8.8) | 1.4% | — | Craftcms Craft CMS | 12/5/2023 | 17/6/2026 | An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter. | |
| Modificada | Media (6.1) | 0.41% | — | Craftcms Craft CMS | 9/5/2023 | 17/6/2026 | Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4. | |
| Modificada | Media (6.1) | 0.40% | — | Craftcms Craft CMS | 25/4/2023 | 17/6/2026 | CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name. | |
| Modificada | Alta (8.8) | 3.6% | — | Kiwitcms Kiwi Tcms | 24/4/2023 | 17/6/2026 | Kiwi TCMS is an open source test management system. In kiwitcms/Kiwi v12.2 and prior and kiwitcms/enterprise v12.2 and prior, the `changelog.yml` workflow is vulnerable to command injection attacks because of using an untrusted `github.head_ref` field. The `github.head_ref` value is an attacker-controlled value.… | |
| Analizada | Crítica (9) | 1.0% | — | Kiwitcms Kiwi Tcms | 24/4/2023 | 17/6/2026 | Kiwi TCMS, an open source test management system, allows users to upload attachments to test plans, test cases, etc. In versions of Kiwi TCMS prior to 12.2, there is no control over what kinds of files can be uploaded. Thus, a malicious actor may upload an `.exe` file or a file containing embedded JavaScript and trick… | |
| Modificada | Media (4.3) | 0.42% | — | Kiwitcms Kiwi Tcms | 24/4/2023 | 17/6/2026 | Kiwi TCMS is an open source test management system. In versions of Kiwi TCMS prior to 12.2, users were able to update their email addresses via the `My profile` admin page. This page allowed them to change the email address registered with their account without the ownership verification performed during account… | |
| Modificada | Crítica (9.8) | 0.87% | — | Otcms | 2/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality of the file sysCheckFile.php?mudi=sql. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.4) | 0.48% | — | Kiwitcms Kiwi Tcms | 29/3/2023 | 17/6/2026 | Kiwi TCMS is an open source test management system for both manual and automated testing. Kiwi TCMS accepts SVG files uploaded by users which could potentially contain JavaScript code. If SVG images are viewed directly, i.e. not rendered in an HTML page, this JavaScript code could execute. This vulnerability has been… | |
| Modificada | Media (6.1) | 0.62% | — | Otcms | 25/3/2023 | 17/6/2026 | A vulnerability was found in OTCMS 6.72. It has been declared as problematic. Affected by this vulnerability is the function AutoRun of the file apiRun.php. The manipulation of the argument mode leads to cross site scripting. The attack can be launched remotely. The identifier VDB-224017 was assigned to this… | |
| Modificada | Crítica (9.8) | 0.74% | — | Otcms | 25/3/2023 | 17/6/2026 | A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the component URL Parameter Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 1.3% | — | Lightcms Project Lightcms | 22/3/2023 | 17/6/2026 | LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function. | |
| Modificada | Alta (7.2) | 0.91% | — | Xjd2020 Fastcms | 6/3/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in fastcms. This affects an unknown part of the file admin/TemplateController.java of the component ZIP File Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (5.4) | 0.80% | — | Craftcms Craft CMS | 3/3/2023 | 17/6/2026 | Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been fixed in version 4.3.7. | |
| Modificada | Alta (7.5) | 0.60% | — | Exponentcms Exponent CMS | 17/2/2023 | 17/6/2026 | SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class. | |
| Modificada | Media (5.9) | 0.92% | — | Kiwitcms Kiwi Tcms | 15/2/2023 | 17/6/2026 | Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt denial-of-service attacks against the Password reset page. An attacker could potentially send a large number of emails if they know the email addresses of users in Kiwi TCMS.… |