Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.99% | — | Tpcms Project Tpcms | 4/4/2022 | 17/6/2026 | TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password. | |
| Modificada | Media (4.8) | 0.44% | — | Tpcms Project Tpcms | 4/4/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in TPCMS v3.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Phone text box. | |
| Modificada | Alta (8.8) | 1.8% | — | Wpanel CMS Project Wpanel CMS | 31/3/2022 | 17/6/2026 | Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image. | |
| Modificada | Media (5.4) | 0.56% | — | Classcms Project Classcms | 25/3/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Column module of ClassCMS v2.5 and below allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Articles field. | |
| Modificada | Alta (8.8) | 0.48% | — | Xiaohuanxiong CMS Project Xiaohuanxiong CMS | 23/3/2022 | 17/6/2026 | An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account. | |
| Modificada | Crítica (9.8) | 1.6% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file. | |
| Modificada | Media (6.1) | 0.68% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information through SQL injection statements. | |
| Modificada | Crítica (9.8) | 1.3% | — | Luocms Project Luocms | 10/3/2022 | 17/6/2026 | Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements. | |
| Modificada | Crítica (9.8) | 1.5% | — | Victor CMS Project Victor CMS | 4/3/2022 | 17/6/2026 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability. | |
| Modificada | Alta (7.2) | 1.9% | — | Ayacms Project Ayacms | 1/3/2022 | 17/6/2026 | AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php, | |
| Modificada | Alta (7.5) | 1.1% | — | Horizontcms Project Horizontcms | 24/2/2022 | 17/6/2026 | HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/. | |
| Modificada | Alta (8.8) | 1.1% | — | Baicloud-cms Project Baicloud-cms | 19/2/2022 | 17/6/2026 | BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Duxcms Project Duxcms | 16/2/2022 | 17/6/2026 | DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=. | |
| Modificada | Alta (8.8) | 1.3% | — | Victor CMS Project Victor CMS | 3/2/2022 | 17/6/2026 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability that allows attackers to inject arbitrary commands via 'user_firstname' parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Victor CMS Project Victor CMS | 31/1/2022 | 17/6/2026 | Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters. | |
| Modificada | Alta (7.5) | 1.4% | — | Victor CMS Project Victor CMS | 31/1/2022 | 17/6/2026 | Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter. | |
| Modificada | Alta (7.2) | 1.2% | — | Useful Simple Open-source CMS Project Useful Simple Open-source CMS | 10/1/2022 | 17/6/2026 | Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer version. USOC version Pb2.4Bfx3 contains a… | |
| Modificada | Alta (7.2) | 1.0% | — | Useful Simple Open-source CMS Project Useful Simple Open-source CMS | 4/1/2022 | 17/6/2026 | USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via usersearch.php. In search terms provided by the user were not sanitized and were used directly to construct a sql statement. The only users permitted to search are site admins. Users are advised to upgrade as… |