Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

595 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.91%—Kiwitcms Kiwi Tcms15/2/202317/6/2026
Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a workaround, users may install and configure a rate-limiting proxy in front…
ModificadaCrítica (9.8)1.2%—Pbootcms3/2/202317/6/2026
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
ModificadaMedia (5.3)0.76%—Fastcms Project Fastcms2/2/202317/6/2026
A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
ModificadaMedia (5.3)0.88%—Dotcms1/2/202317/6/2026
In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests.
ModificadaMedia (6.5)8.5%—Dotcms1/2/202317/6/2026
An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote Code Execution.
ModificadaAlta (8.8)0.64%💥 PoCDotcms1/2/202317/6/2026
An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover.
ModificadaMedia (6.5)0.87%—Dotcms1/2/202317/6/2026
In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to local IP addresses or private subnets. In resolving this URL, the TempFileAPI follows any 302 redirects that the remote URL returns. Because there is no re-validation of the…
ModificadaAlta (8.8)0.68%—Kiwitcms Kiwi Tcms2/1/202317/6/2026
Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to guess password. This issue is resolved by providing defaults for the `AUTH_PASSWORD_VALIDATORS`…
ModificadaAlta (8.8)0.85%—Xjd2020 Fastcms6/12/202217/6/2026
A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the file /template/edit of the component Template Handler. The manipulation leads to injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaAlta (7.5)1.1%—Craftcms Craft CMS5/12/202217/6/2026
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The…
ModificadaAlta (7.2)0.75%—Jrecms Springbootcms5/12/202217/6/2026
A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functionality of the component Template Management. The manipulation leads to injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214790 is the…
ModificadaMedia (5.4)0.49%—Kiwitcms Kiwi Tcms21/11/202217/6/2026
A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page.
ModificadaMedia (6.1)1.3%—Dotcms10/11/202217/6/2026
dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using a semicolon in a URL to introduce a matrix parameter. (This is also fixed in 5.3.8.12, 21.06.9, and 22.03.2 for LTS users.) Some Java application frameworks, including those used by Spring or Tomcat,…
ModificadaMedia (5.4)0.51%—Craftcms Craft CMS21/9/202217/6/2026
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
ModificadaMedia (5.4)0.50%—Craftcms Craft CMS16/9/20229/7/2026
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
ModificadaMedia (5.4)0.57%—Craftcms Craft CMS16/9/202217/6/2026
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
ModificadaMedia (5.4)0.66%—Craftcms Craft CMS16/9/202217/6/2026
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
ModificadaMedia (5.4)0.67%—Craftcms Craft CMS16/9/202217/6/2026
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
ModificadaMedia (6.1)0.58%—Ftcms7/9/202217/6/2026
ftcms 2.1 poster.PHP has a XSS vulnerability. The attacker inserts malicious JavaScript code into the web page, causing the user / administrator to trigger malicious code when accessing.
ModificadaAlta (8.8)0.40%—Ftcms7/9/202217/6/2026
In ftcms 2.1, there is a Cross Site Request Forgery (CSRF) vulnerability in the PHP page, which causes the attacker to forge a link to trick him to click on a malicious link or visit a page containing attack code, and send a request to the server (corresponding to the identity authentication information) as the victim…
ModificadaMedia (6.1)0.65%—Dotcms5/8/202217/6/2026
A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has XSS_PROTECTION_ENABLED=false. NOTE: the vendor disputes this because the current product behavior, in effect, has XSS_PROTECTION_ENABLED=true in all configurations
ModificadaCrítica (9.1)0.85%—Boltcms Bolt1/8/20229/7/2026
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.
AnalizadaCrítica (9.8)91%⚠ Explotación activa💥 ExploitDotcms17/7/202217/6/2026
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is…
ModificadaCrítica (9.8)35%—Pbootcms14/7/202217/6/2026
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.
ModificadaMedia (4.8)0.52%—Lightcms Project Lightcms27/6/20229/7/2026
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.