Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.91% | — | Kiwitcms Kiwi Tcms | 15/2/2023 | 17/6/2026 | Kiwi TCMS, an open source test management system, does not impose rate limits in versions prior to 12.0. This makes it easier to attempt brute-force attacks against the login page. Users should upgrade to v12.0 or later to receive a patch. As a workaround, users may install and configure a rate-limiting proxy in front… | |
| Modificada | Crítica (9.8) | 1.2% | — | Pbootcms | 3/2/2023 | 17/6/2026 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request. | |
| Modificada | Media (5.3) | 0.76% | — | Fastcms Project Fastcms | 2/2/2023 | 17/6/2026 | A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (5.3) | 0.88% | — | Dotcms | 1/2/2023 | 17/6/2026 | In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to download a large file. If done repeatedly, this will result in Tomcat request-thread exhaustion and ultimately a denial of any other requests. | |
| Modificada | Media (6.5) | 8.5% | — | Dotcms | 1/2/2023 | 17/6/2026 | An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the dotCMS API can lead to Remote Code Execution. | |
| Modificada | Alta (8.8) | 0.64% | 💥 PoC | Dotcms | 1/2/2023 | 17/6/2026 | An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure random generation algorithm for password-reset token generation leads to account takeover. | |
| Modificada | Media (6.5) | 0.87% | — | Dotcms | 1/2/2023 | 17/6/2026 | In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to block any SSRF access to local IP addresses or private subnets. In resolving this URL, the TempFileAPI follows any 302 redirects that the remote URL returns. Because there is no re-validation of the… | |
| Modificada | Alta (8.8) | 0.68% | — | Kiwitcms Kiwi Tcms | 2/1/2023 | 17/6/2026 | Kiwi TCMS is an open source test management system. In version 11.6 and prior, when users register new accounts and/or change passwords, there is no validation in place which would prevent them from picking an easy to guess password. This issue is resolved by providing defaults for the `AUTH_PASSWORD_VALIDATORS`… | |
| Modificada | Alta (8.8) | 0.85% | — | Xjd2020 Fastcms | 6/12/2022 | 17/6/2026 | A vulnerability was found in FastCMS. It has been rated as critical. This issue affects some unknown processing of the file /template/edit of the component Template Handler. The manipulation leads to injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (7.5) | 1.1% | — | Craftcms Craft CMS | 5/12/2022 | 17/6/2026 | All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The… | |
| Modificada | Alta (7.2) | 0.75% | — | Jrecms Springbootcms | 5/12/2022 | 17/6/2026 | A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functionality of the component Template Management. The manipulation leads to injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-214790 is the… | |
| Modificada | Media (5.4) | 0.49% | — | Kiwitcms Kiwi Tcms | 21/11/2022 | 17/6/2026 | A stored XSS in a kiwi Test Plan can run malicious javascript which could be chained with an HTML injection to perform a UI redressing attack (clickjacking) and an HTML injection which disables the use of the history page. | |
| Modificada | Media (6.1) | 1.3% | — | Dotcms | 10/11/2022 | 17/6/2026 | dotCMS before 22.06 allows remote attackers to bypass intended access control and obtain sensitive information by using a semicolon in a URL to introduce a matrix parameter. (This is also fixed in 5.3.8.12, 21.06.9, and 22.03.2 for LTS users.) Some Java application frameworks, including those used by Spring or Tomcat,… | |
| Modificada | Media (5.4) | 0.51% | — | Craftcms Craft CMS | 21/9/2022 | 17/6/2026 | Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label. | |
| Modificada | Media (5.4) | 0.50% | — | Craftcms Craft CMS | 16/9/2022 | 9/7/2026 | Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. | |
| Modificada | Media (5.4) | 0.57% | — | Craftcms Craft CMS | 16/9/2022 | 17/6/2026 | Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page. | |
| Modificada | Media (5.4) | 0.66% | — | Craftcms Craft CMS | 16/9/2022 | 17/6/2026 | Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php. | |
| Modificada | Media (5.4) | 0.67% | — | Craftcms Craft CMS | 16/9/2022 | 17/6/2026 | Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount. | |
| Modificada | Media (6.1) | 0.58% | — | Ftcms | 7/9/2022 | 17/6/2026 | ftcms 2.1 poster.PHP has a XSS vulnerability. The attacker inserts malicious JavaScript code into the web page, causing the user / administrator to trigger malicious code when accessing. | |
| Modificada | Alta (8.8) | 0.40% | — | Ftcms | 7/9/2022 | 17/6/2026 | In ftcms 2.1, there is a Cross Site Request Forgery (CSRF) vulnerability in the PHP page, which causes the attacker to forge a link to trick him to click on a malicious link or visit a page containing attack code, and send a request to the server (corresponding to the identity authentication information) as the victim… | |
| Modificada | Media (6.1) | 0.65% | — | Dotcms | 5/8/2022 | 17/6/2026 | A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin portal when the configuration has XSS_PROTECTION_ENABLED=false. NOTE: the vendor disputes this because the current product behavior, in effect, has XSS_PROTECTION_ENABLED=true in all configurations | |
| Modificada | Crítica (9.1) | 0.85% | — | Boltcms Bolt | 1/8/2022 | 9/7/2026 | The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input. | |
| Analizada | Crítica (9.8) | 91% | ⚠ Explotación activa💥 Exploit | Dotcms | 17/7/2022 | 17/6/2026 | An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is… | |
| Modificada | Crítica (9.8) | 35% | — | Pbootcms | 14/7/2022 | 17/6/2026 | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php. | |
| Modificada | Media (4.8) | 0.52% | — | Lightcms Project Lightcms | 27/6/2022 | 9/7/2026 | A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file. |