Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Waimai Super CMS Project Waimai Super CMS5/10/202117/6/2026
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the product is sold for free.
ModificadaMedia (6.5)0.94%—Hongcms Project Hongcms4/10/202117/6/2026
HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.
ModificadaCrítica (9.8)1.1%—Flamecms Project Flamecms30/9/202117/6/2026
FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php.
ModificadaCrítica (9.8)0.99%—Flamecms Project Flamecms30/9/202117/6/2026
FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter.
ModificadaCrítica (9.1)1.0%—Baicloud-cms Project Baicloud-cms30/9/202117/6/2026
BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php.
ModificadaMedia (5.4)0.50%—Ucms Project Ucms29/9/202117/6/2026
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
ModificadaMedia (5.4)0.60%—Laracms Project Laracms29/9/202117/6/2026
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web scripts or HTML via a crafted payload in the page management module.
ModificadaMedia (5.4)0.60%—Laracms Project Laracms29/9/202117/6/2026
LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor.
ModificadaAlta (7.5)0.80%—Laracms Project Laracms29/9/202117/6/2026
LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers.
ModificadaCrítica (9.8)1.6%—Frogcms Project Frogcms23/9/202117/6/2026
Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.
ModificadaMedia (5.4)0.58%—Rgcms Project Rgcms15/9/202117/6/2026
A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board module
ModificadaAlta (7.2)1.7%—Rgcms Project Rgcms15/9/202117/6/2026
An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a PHP file.
ModificadaAlta (7.2)1.7%—Rgcms Project Rgcms15/9/202117/6/2026
An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (6.1)1.0%—Wenkucms Project Wenkucms15/9/202117/6/2026
Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.
ModificadaMedia (5.7)0.31%—Dswjcms Project Dswjcms9/9/202117/6/2026
A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users.
ModificadaCrítica (9.8)1.6%—Dswjcms Project Dswjcms9/9/202117/6/2026
An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.
ModificadaMedia (6.1)0.64%—Dswjcms Project Dswjcms9/9/202117/6/2026
A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.
ModificadaMedia (6.1)0.64%—Dswjcms Project Dswjcms9/9/202117/6/2026
A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML.
ModificadaCrítica (9.8)1.1%—Bluecms Project Bluecms8/9/202117/6/2026
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
ModificadaMedia (5.4)0.53%—Wtcms Project Wtcms1/9/202117/6/2026
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
ModificadaMedia (5.4)0.53%—Wtcms Project Wtcms1/9/202117/6/2026
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
ModificadaMedia (5.4)0.50%—Wtcms Project Wtcms1/9/202117/6/2026
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
ModificadaMedia (5.4)0.55%—Wtcms Project Wtcms1/9/20219/7/2026
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
ModificadaMedia (5.4)0.50%—Wtcms Project Wtcms1/9/202117/6/2026
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.
ModificadaMedia (6.5)0.43%—Wtcms Project Wtcms1/9/202117/6/2026
WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.
Orbitaley — Vulnerabilidades