Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Useful Simple Open-source CMS Project Useful Simple Open-source CMS | 4/1/2022 | 17/6/2026 | USOC is an open source CMS with a focus on simplicity. In affected versions USOC allows for SQL injection via register.php. In particular usernames, email addresses, and passwords provided by the user were not sanitized and were used directly to construct a sql statement. Users are advised to upgrade as soon as… | |
| Modificada | Media (6.1) | 0.56% | — | Personal Blog CMS Project Personal Blog CMS | 22/12/2021 | 17/6/2026 | Blog CMS v1.0 contains a cross-site scripting (XSS) vulnerability in the /controller/CommentAdminController.java component. | |
| Modificada | Alta (7.5) | 0.98% | — | Php-cms Project Php-cms | 3/11/2021 | 17/6/2026 | PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information. | |
| Modificada | Crítica (9.8) | 0.99% | — | Ed01-cms Project Ed01-cms | 3/11/2021 | 17/6/2026 | ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter. | |
| Modificada | Crítica (9.8) | 1.4% | — | Ed01-cms Project Ed01-cms | 3/11/2021 | 17/6/2026 | An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands. | |
| Modificada | Media (6.1) | 0.64% | — | Ed01-cms Project Ed01-cms | 3/11/2021 | 17/6/2026 | ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Post title or Post content fields. | |
| Modificada | Alta (8.8) | 0.59% | — | Ayacms Project Ayacms | 2/11/2021 | 17/6/2026 | Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts. | |
| Modificada | Crítica (9.8) | 1.6% | — | Doyocms Project Doyocms | 1/11/2021 | 17/6/2026 | Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.7% | — | Doyocms Project Doyocms | 1/11/2021 | 17/6/2026 | SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter. | |
| Modificada | Media (6.5) | 1.2% | — | Baijiacms Project Baijiacms | 29/10/2021 | 17/6/2026 | A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 which allows attackers to arbitrarily delete folders on the server via the "id" parameter. | |
| Modificada | Media (4.9) | 1.2% | — | Frogcms Project Frogcms | 29/10/2021 | 17/6/2026 | A vulnerability exists within the FileManagerController.php function in FrogCMS 0.9.5 which allows an attacker to perform a directory traversal attack via a GET request urlencode parameter. | |
| Modificada | Crítica (9.8) | 3.3% | — | Mara CMS Project Mara CMS | 28/10/2021 | 17/6/2026 | A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file. | |
| Modificada | Media (5.4) | 0.52% | — | Mara CMS Project Mara CMS | 28/10/2021 | 17/6/2026 | A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Media (6.1) | 0.74% | — | Macs CMS Project Macs CMS | 22/10/2021 | 17/6/2026 | Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module. | |
| Modificada | Alta (7.2) | 1.1% | — | Macs CMS Project Macs CMS | 22/10/2021 | 17/6/2026 | Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules. | |
| Modificada | Media (5.4) | 0.58% | — | Chaoji CMS Project Chaoji CMS | 14/10/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts. | |
| Modificada | Crítica (9.8) | 2.0% | — | Thinkphp50-cms Project Thinkphp50-cms | 7/10/2021 | 17/6/2026 | ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha. | |
| Modificada | Crítica (9.1) | 1.2% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method. | |
| Modificada | Crítica (9.8) | 2.8% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method. | |
| Modificada | Crítica (9.8) | 3.3% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method. | |
| Modificada | Alta (8.8) | 3.2% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method. | |
| Modificada | Alta (8.1) | 0.83% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method. | |
| Modificada | Media (6.1) | 0.66% | — | Waimai Super CMS Project Waimai Super CMS | 5/10/2021 | 17/6/2026 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?m=Config&a=add. | |
| Modificada | Media (6.1) | 0.66% | — | Waimai Super CMS Project Waimai Super CMS | 5/10/2021 | 17/6/2026 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php/Link/addsave. | |
| Modificada | Media (6.1) | 0.66% | — | Waimai Super CMS Project Waimai Super CMS | 5/10/2021 | 17/6/2026 | waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?&m=Public&a=login. |