Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Waimai Super CMS Project Waimai Super CMS | 5/10/2021 | 17/6/2026 | waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=addsave credit parameter to -1, the product is sold for free. | |
| Modificada | Media (6.5) | 0.94% | — | Hongcms Project Hongcms | 4/10/2021 | 17/6/2026 | HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit. | |
| Modificada | Crítica (9.8) | 1.1% | — | Flamecms Project Flamecms | 30/9/2021 | 17/6/2026 | FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php. | |
| Modificada | Crítica (9.8) | 0.99% | — | Flamecms Project Flamecms | 30/9/2021 | 17/6/2026 | FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter. | |
| Modificada | Crítica (9.1) | 1.0% | — | Baicloud-cms Project Baicloud-cms | 30/9/2021 | 17/6/2026 | BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php. | |
| Modificada | Media (5.4) | 0.50% | — | Ucms Project Ucms | 29/9/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields. | |
| Modificada | Media (5.4) | 0.60% | — | Laracms Project Laracms | 29/9/2021 | 17/6/2026 | LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows atackers to execute arbitrary web scripts or HTML via a crafted payload in the page management module. | |
| Modificada | Media (5.4) | 0.60% | — | Laracms Project Laracms | 29/9/2021 | 17/6/2026 | LaraCMS v1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the content editor. | |
| Modificada | Alta (7.5) | 0.80% | — | Laracms Project Laracms | 29/9/2021 | 17/6/2026 | LaraCMS v1.0.1 transmits sensitive information in cleartext which can be intercepted by attackers. | |
| Modificada | Crítica (9.8) | 1.6% | — | Frogcms Project Frogcms | 23/9/2021 | 17/6/2026 | Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file. | |
| Modificada | Media (5.4) | 0.58% | — | Rgcms Project Rgcms | 15/9/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board module | |
| Modificada | Alta (7.2) | 1.7% | — | Rgcms Project Rgcms | 15/9/2021 | 17/6/2026 | An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a PHP file. | |
| Modificada | Alta (7.2) | 1.7% | — | Rgcms Project Rgcms | 15/9/2021 | 17/6/2026 | An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (6.1) | 1.0% | — | Wenkucms Project Wenkucms | 15/9/2021 | 17/6/2026 | Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'. | |
| Modificada | Media (5.7) | 0.31% | — | Dswjcms Project Dswjcms | 9/9/2021 | 17/6/2026 | A cross-site request forgery (CSRF) in index.php/Dswjcms/User/tfAdd of Dswjcms 1.6.4 allows authenticated attackers to arbitrarily add administrator users. | |
| Modificada | Crítica (9.8) | 1.6% | — | Dswjcms Project Dswjcms | 9/9/2021 | 17/6/2026 | An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Modificada | Media (6.1) | 0.64% | — | Dswjcms Project Dswjcms | 9/9/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Site/articleList component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (6.1) | 0.64% | — | Dswjcms Project Dswjcms | 9/9/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the index.php/Dswjcms/Basis/links component of Dswjcms 1.6.4 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Crítica (9.8) | 1.1% | — | Bluecms Project Bluecms | 8/9/2021 | 17/6/2026 | BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php. | |
| Modificada | Media (5.4) | 0.53% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module. | |
| Modificada | Media (5.4) | 0.53% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module. | |
| Modificada | Media (5.4) | 0.50% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module. | |
| Modificada | Media (5.4) | 0.55% | — | Wtcms Project Wtcms | 1/9/2021 | 9/7/2026 | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box. | |
| Modificada | Media (5.4) | 0.50% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module. | |
| Modificada | Media (6.5) | 0.43% | — | Wtcms Project Wtcms | 1/9/2021 | 17/6/2026 | WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background. |