Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)2.1%💥 ExploitWuzhicms24/4/201817/6/2026
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.
ModificadaAlta (8.8)2.3%💥 ExploitWuzhicms24/4/201817/6/2026
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
ModificadaMedia (6.1)2.4%💥 ExploitWuzhicms24/4/201817/6/2026
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.
ModificadaMedia (6.1)0.79%—1234n Minicms22/4/201817/6/2026
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.
ModificadaMedia (5.4)0.61%—Icmsdev Icms20/4/201817/6/2026
iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.
ModificadaMedia (6.5)0.54%—Wuzhicms20/4/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can delete any article via index.php?m=content&f=content&v=recycle_delete.
ModificadaMedia (5.4)0.66%—1234n Minicms19/4/201817/6/2026
MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.
ModificadaAlta (8.8)0.59%—Icmsdev Icms19/4/201817/6/2026
An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP.
ModificadaMedia (5.4)0.66%—Wuzhicms19/4/201817/6/2026
An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lower than the administrator) logs in, he can add a new TAGS with…
ModificadaAlta (8.8)0.51%—Tuzicms17/4/201817/6/2026
An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated by a history.pushState call.
ModificadaAlta (8.8)0.53%—Icmsdev Icms16/4/201817/6/2026
An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&frame=iPHP.
ModificadaAlta (8.8)0.69%—Wuzhicms10/4/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.
ModificadaAlta (8.8)2.9%💥 ExploitWuzhicms10/4/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.
ModificadaMedia (5.4)0.62%—Icmsdev Icms10/4/201817/6/2026
An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=save&frame=iPHP request.
ModificadaCrítica (9.8)1.4%—Icmsdev Icms10/4/201817/6/2026
An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request.
ModificadaAlta (8.8)0.60%—Icmsdev Icms10/4/201817/6/2026
An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save&frame=iPHP request.
ModificadaMedia (5.3)1.1%—Icmsdev Icms10/4/201817/6/2026
An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname.
ModificadaAlta (8.8)2.7%💥 Exploit1234n Minicms27/3/201817/6/2026
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
ModificadaAlta (7.5)2.7%💥 ExploitJessgramp Minicms1/10/201216/6/2026
miniCMS 1.0 and 2.0 allows remote attackers to execute arbitrary PHP code via a crafted (1) pagename or (2) area variable containing an executable extension, which is not properly handled by (a) update.php when writing files to content/, or (b) updatenews.php when writing files to content/news/.
ModificadaMedia (5)2.4%💥 ExploitLokicms7/4/200916/6/2026
LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request to admin.php.
ModificadaMedia (5)6.4%💥 ExploitLokicms26/1/200916/6/2026
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a .. (dot dot) in the page parameter.
ModificadaMedia (5)2.7%💥 ExploitLokicms4/11/200816/6/2026
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.
ModificadaMedia (6.8)2.4%💥 ExploitLokicms22/10/200816/6/2026
Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.
ModificadaAlta (7.5)2.5%💥 ExploitAsicms9/10/200816/6/2026
Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[asicms][path] parameter to (1) Association.php, (2) BigMath.php, (3) DiffieHellman.php, (4) DumbStore.php, (5) Extension.php, (6) FileStore.php, (7) HMAC.php, (8)…
ModificadaAlta (7.5)3.1%💥 ExploitGapi CMS Gapicms15/7/200816/6/2026
PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the dirDepth parameter.