Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

824 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.55%—Concretecms Concrete CMS29/2/202417/6/2026
Concrete CMS before 9.2.3 allows Stored XSS on the Admin Dashboard via /dashboard/system/basics/name. (8.5 and earlier are unaffected.)
AnalizadaMedia (4.3)0.28%—Concretecms Concrete CMS29/2/202417/6/2026
Concrete CMS before 8.5.14 and 9 before 9.2.3 allows Cross Site Request Forgery (CSRF) via ccm/calendar/dialogs/event/delete/submit. An attacker can force an admin to delete events on the site because the event ID is numeric and sequential.
AnalizadaMedia (4.3)0.28%—Concretecms Concrete CMS29/2/202417/6/2026
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) at /ccm/system/dialogs/file/delete/1/submit.
AnalizadaMedia (4.8)0.49%—Concretecms Concrete CMS29/2/202417/6/2026
Concrete CMS before 8.5.14 and 9 before 9.2.3 is vulnerable to an admin adding a stored XSS payload via the Layout Preset name.
AnalizadaAlta (8.8)0.23%—Dedecms28/2/202417/6/2026
Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.
AnalizadaMedia (5.3)1.0%—Apostrophecms Sanitize-htmlFedoraproject Fedora24/2/202417/6/2026
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system…
ModificadaMedia (4.8)0.45%—Concretecms Concrete CMS9/2/202417/6/2026
Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided data. A rogue administrator could inject malicious code when importing images, leading to the execution of the malicious code on the website user’s browser.…
ModificadaMedia (4.8)0.40%—Concretecms Concrete CMS9/2/202417/6/2026
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently sanitized in the Edit Attributes page. A rogue administrator could put malicious code into the file tags or description attributes and, when another…
ModificadaMedia (4.8)1.2%💥 PoCConcretecms Concrete CMS9/2/202417/6/2026
Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient validation of administrator provided data for that field. A rogue administrator could inject malicious code into the Role Name field which might be executed when users visit the affected page. The…
ModificadaAlta (7.2)1.5%—Unitecms Unlimited Addons FOR Wpbakery Page Builder5/2/202417/6/2026
The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' function in versions up to, and including, 1.0.42. This makes it possible for authenticated attackers with a role that the administrator previously…
ModificadaAlta (8.8)0.77%—Dedecms22/1/202417/6/2026
DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.
ModificadaMedia (6.1)0.39%—Elitecms Elite CMS11/1/202417/6/2026
Cross Site Scripting Vulnerability in Elite CRM v1.2.11 allows attacker to execute arbitrary code via the language parameter to the /ngs/login endpoint.
ModificadaAlta (7.2)0.98%—Phome Empirecms9/1/202417/6/2026
SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function.
ModificadaMedia (5.4)0.33%—Get-simple Getsimplecms8/1/202417/6/2026
A Cross Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.16 exists when using Source Code Mode as a backend user to add articles via the /admin/edit.php page.
ModificadaCrítica (9.8)0.59%—Dedecms7/1/202417/6/2026
A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component Backend. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
ModificadaMedia (4.3)0.23%—Concretecms Concrete CMS25/12/202317/6/2026
Concrete CMS 9 before 9.2.3 is vulnerable to Cross Site Request Forgery (CSRF) via /ccm/system/dialogs/logs/delete_all/submit. An attacker can force an admin user to delete server report logs on a web application to which they are currently authenticated.
ModificadaCrítica (9.8)0.63%—Leadscloud Empirecms14/12/202317/6/2026
EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.
ModificadaMedia (4.3)0.69%—Thecosy Icecms13/12/202317/6/2026
A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /article/DelectArticleById/ of the component Article Handler. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed to…
ModificadaAlta (8.8)0.79%—Thecosy Icecms13/12/202317/6/2026
A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and…
ModificadaMedia (5.4)0.64%—Thecosy Icecms13/12/202317/6/2026
A vulnerability classified as critical was found in Thecosy IceCMS up to 2.0.1. This vulnerability affects unknown code. The manipulation leads to manage user sessions. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247888.
ModificadaAlta (7.5)0.97%—Thecosy Icecms13/12/202317/6/2026
A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. This affects an unknown part of the file /WebResource/resource of the component Love Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (4.3)0.74%—Thecosy Icecms13/12/202317/6/2026
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to…
ModificadaMedia (6.5)0.98%—Thecosy Icecms13/12/202317/6/2026
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /adplanet/PlanetUser of the component API. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed…
ModificadaCrítica (9.8)1.3%—Thecosy Icecms13/12/202317/6/2026
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The exploit…
ModificadaMedia (6.1)1.1%💥 ExploitDedecms11/12/20239/7/2026
DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php.