Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.99%—Tpcms Project Tpcms4/4/202217/6/2026
TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.
ModificadaMedia (4.8)0.44%—Tpcms Project Tpcms4/4/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Phone text box.
ModificadaAlta (8.8)1.8%—Wpanel CMS Project Wpanel CMS31/3/202217/6/2026
Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.
ModificadaMedia (5.4)0.56%—Classcms Project Classcms25/3/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Articles field.
ModificadaAlta (8.8)0.48%—Xiaohuanxiong CMS Project Xiaohuanxiong CMS23/3/202217/6/2026
An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.
ModificadaCrítica (9.8)1.6%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.
ModificadaMedia (6.1)0.68%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
ModificadaCrítica (9.8)1.2%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
ModificadaCrítica (9.8)1.2%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
ModificadaCrítica (9.8)1.2%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
ModificadaCrítica (9.8)1.2%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
ModificadaCrítica (9.8)1.2%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
ModificadaCrítica (9.8)1.2%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
ModificadaAlta (7.5)1.2%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements.
ModificadaCrítica (9.8)1.3%—Luocms Project Luocms10/3/202217/6/2026
Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.
ModificadaCrítica (9.8)1.5%—Victor CMS Project Victor CMS4/3/202217/6/2026
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.
ModificadaAlta (7.2)1.9%—Ayacms Project Ayacms1/3/202217/6/2026
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,
ModificadaAlta (7.5)1.1%—Horizontcms Project Horizontcms24/2/202217/6/2026
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.
ModificadaAlta (8.8)1.1%—Baicloud-cms Project Baicloud-cms19/2/202217/6/2026
BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php.
ModificadaCrítica (9.8)1.2%—Duxcms Project Duxcms16/2/202217/6/2026
DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.
ModificadaAlta (8.8)1.3%—Victor CMS Project Victor CMS3/2/202217/6/2026
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter.
ModificadaAlta (7.5)1.4%—Victor CMS Project Victor CMS31/1/202217/6/2026
Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.
ModificadaAlta (7.5)1.4%—Victor CMS Project Victor CMS31/1/202217/6/2026
Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter.
ModificadaAlta (7.2)1.2%—Useful Simple Open-source CMS Project Useful Simple Open-source CMS10/1/202217/6/2026
Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer version. USOC version Pb2.4Bfx3 contains a…
ModificadaAlta (7.2)1.0%—Useful Simple Open-source CMS Project Useful Simple Open-source CMS4/1/202217/6/2026
USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site admins. Users are advised to upgrade as…
Orbitaley — Vulnerabilidades