Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.43% | — | Dedecms | 7/12/2023 | 17/6/2026 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the v parameter at selectimages.php. | |
| Modificada | Media (6.1) | 0.43% | — | Dedecms | 7/12/2023 | 17/6/2026 | DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php. | |
| Modificada | Baja (3.7) | 0.62% | — | Thecosy Icecms | 2/12/2023 | 17/6/2026 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /Websquare/likeClickComment/ of the component Comment Like Handler. The manipulation leads to improper enforcement of a single, unique action. The attack may be initiated… | |
| Modificada | Media (6.1) | 0.61% | — | Thecosy Icecms | 2/12/2023 | 17/6/2026 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. This vulnerability affects unknown code of the file /planet of the component User Comment Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.3) | 0.70% | — | Thecosy Icecms | 30/11/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /WebArticle/articles/ of the component Like Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.97% | — | Get-simple Getsimplecms | 17/11/2023 | 17/6/2026 | A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.4) | 0.59% | — | Concretecms Concrete CMS | 17/11/2023 | 17/6/2026 | Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows stored XSS on the Admin page via an uploaded file name. | |
| Modificada | Crítica (9.8) | 1.2% | — | Concretecms Concrete CMS | 17/11/2023 | 17/6/2026 | Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can be granted when creating a directory… | |
| Modificada | Alta (8.8) | 0.32% | — | Dedecms | 16/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form. | |
| Modificada | Media (5.4) | 0.41% | — | Dedecms | 13/11/2023 | 17/6/2026 | DedeCMS v6.2 was discovered to contain a Cross-site Scripting (XSS) vulnerability via spec_add.php. | |
| Modificada | Media (5.4) | 0.61% | — | Bigtreecms Bigtree CMS | 1/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings functions. | |
| Modificada | Media (5.4) | 0.50% | — | Get-simple Getsimplecms | 31/10/2023 | 17/6/2026 | Cross Site Scripting vulnerability in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via the a crafted payload to the components.php function. | |
| Modificada | Media (6.5) | 0.22% | — | Macwk Icecms | 27/10/2023 | 17/6/2026 | IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Media (4.8) | 0.46% | 💥 PoC | Ritecms | 25/10/2023 | 17/6/2026 | A File upload vulnerability in RiteCMS 3.0 allows a local attacker to upload a SVG file with XSS content. | |
| Modificada | Media (4.8) | 0.64% | 💥 PoC | Concretecms Concrete CMS | 23/10/2023 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS v.9.2.1 allow an attacker to execute arbitrary code via a crafted script to the Header and Footer Tracking Codes of the SEO & Statistics. NOTE: the vendor disputes this because these header/footer changes can only be made by an admin, and allowing an… | |
| Modificada | Crítica (9.8) | 23% | — | Get-simple Getsimplecms | 19/10/2023 | 17/6/2026 | An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo(). | |
| Modificada | Crítica (9.8) | 0.72% | — | Thecosy Icecms | 12/10/2023 | 17/6/2026 | An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting. | |
| Modificada | Media (5.4) | 0.58% | 💥 PoC | Concretecms Concrete CMS | 10/10/2023 | 17/6/2026 | Concrete CMS v9.2.1 is affected by an Arbitrary File Upload vulnerability via a Thumbnail file upload, which allows Cross-Site Scripting (XSS). NOTE: the vendor's position is that a customer is supposed to know that "pdf" should be excluded from the allowed file types, even though pdf is one of the allowed file types… | |
| Modificada | Media (4.8) | 0.60% | 💥 PoC | Concretecms Concrete CMS | 6/10/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS v.9.2.1 allows an attacker to execute arbitrary code via a crafted script to the SEO - Extra from Page Settings. NOTE: the vendor disputes this because this SEO-related header change can only be made by an admin, and allowing an admin to place JavaScript there… | |
| Modificada | Media (5.4) | 0.60% | 💥 PoC | Concretecms Concrete CMS | 6/10/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS versions 8.5.12 and below, and 9.0 through 9.2.1 allows an attacker to execute arbitrary code via a crafted script to Plural Handle of the Data Objects from System & Settings. | |
| Modificada | Media (5.4) | 0.58% | 💥 PoC | Concretecms Concrete CMS | 6/10/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS before 9.2.3 exists via the Name parameter during installation (aka Site of Installation or Settings). | |
| Modificada | Media (5.4) | 0.63% | 💥 PoC | Concretecms Concrete CMS | 6/10/2023 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in Concrete CMS from versions 9.2.0 to 9.2.2 allows an attacker to execute arbitrary code via a crafted script to the Tags from Settings - Tags. | |
| Modificada | Media (5.4) | 0.58% | 💥 PoC | Concretecms Concrete CMS | 6/10/2023 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities in Concrete CMS versions affected to 8.5.13 and below, and 9.0.0 through 9.2.1 allow a local attacker to execute arbitrary code via a crafted script to the Forms of the Data objects. | |
| Modificada | Media (4.8) | 0.55% | 💥 PoC | Ritecms | 4/10/2023 | 17/6/2026 | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a payload crafted in the Home Page fields in the Administration menu. | |
| Modificada | Alta (8.8) | 7.5% | — | Dedecms | 30/9/2023 | 17/6/2026 | A vulnerability classified as critical was found in DedeCMS 5.7.111. This vulnerability affects the function AddMyAddon of the file album_add.php. The manipulation of the argument albumUploadFiles leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… |