Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.52% | — | Beecms | 29/9/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in BEECMS 4.0. This affects an unknown part of the file /admin/admin_content_tag.php?action=save_content. The manipulation of the argument tag leads to cross site scripting. It is possible to initiate the attack remotely.… | |
| Modificada | Alta (7.2) | 0.66% | — | Huakecms | 29/9/2023 | 17/6/2026 | A vulnerability classified as critical was found in huakecms 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/cms_content.php. The manipulation of the argument cid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 0.95% | — | Dedecms | 28/9/2023 | 17/6/2026 | An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Modificada | Media (4.8) | 0.53% | 💥 PoC | Ritecms | 28/9/2023 | 17/6/2026 | Rite CMS 3.0 has a Cross-Site scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload into the Global Content Blocks in the Administration Menu. | |
| Modificada | Media (5.4) | 0.53% | 💥 PoC | Ritecms | 28/9/2023 | 17/6/2026 | Rite CMS 3.0 has Multiple Cross-Site scripting (XSS) vulnerabilities that allow attackers to execute arbitrary code via a crafted payload into the Main Menu Items in the Administration Menu. | |
| Modificada | Media (5.4) | 0.40% | — | Jrecms Springbootcms | 27/9/2023 | 17/6/2026 | SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comments, these malicious codes embedded in the HTML will be executed, and the user's browser will be controlled by the attacker, so as to achieve the special purpose of the attacker, such as cookie theft | |
| Modificada | Alta (8.8) | 0.89% | — | Jrecms Springbootcms | 27/9/2023 | 17/6/2026 | SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by users are not filtered. As a result, special characters in parameters destroy the original logic of SQL statements. Attackers can use this vulnerability to execute any SQL statement. | |
| Modificada | Alta (8.8) | 1.5% | — | Elitecms Elite CMS | 20/9/2023 | 17/6/2026 | A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component. | |
| Modificada | Alta (8.8) | 0.81% | — | Dedecms | 17/9/2023 | 17/6/2026 | A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepath leads to absolute path traversal. The associated identifier of this… | |
| Modificada | Crítica (9.8) | 0.68% | — | Dedecms | 12/9/2023 | 17/6/2026 | DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. | |
| Modificada | Crítica (9.8) | 0.68% | — | Dedecms | 4/9/2023 | 17/6/2026 | A vulnerability classified as critical was found in DedeCMS 5.7.110. This vulnerability affects unknown code of the file /uploads/tags.php. The manipulation of the argument tag_alias leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 0.68% | — | Macwk Icecms | 1/9/2023 | 17/6/2026 | An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser. | |
| Modificada | Media (5.4) | 0.45% | — | Dedecms | 24/8/2023 | 17/6/2026 | DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter. | |
| Modificada | Media (5.4) | 0.45% | — | Dedecms | 24/8/2023 | 17/6/2026 | DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter. | |
| Modificada | Media (5.4) | 0.45% | — | Dedecms | 24/8/2023 | 17/6/2026 | DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters. | |
| Modificada | Media (5.4) | 0.45% | — | Dedecms | 24/8/2023 | 17/6/2026 | DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters. | |
| Modificada | Alta (8.8) | 1.5% | — | Dedecms | 3/8/2023 | 17/6/2026 | DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE). | |
| Modificada | Crítica (9.8) | 1.1% | — | Dedecms | 31/7/2023 | 9/7/2026 | Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php. | |
| Modificada | Crítica (9.8) | 0.80% | — | Yunyecms | 31/7/2023 | 17/6/2026 | SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dedecms | 13/7/2023 | 17/6/2026 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.109 allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Modificada | Crítica (9.8) | 3.6% | 💥 Exploit | Dedecms | 10/7/2023 | 17/6/2026 | A vulnerability classified as critical was found in DedeCMS 5.7.109. Affected by this vulnerability is an unknown functionality of the file co_do.php. The manipulation of the argument rssurl leads to server-side request forgery. The exploit has been disclosed to the public and may be used. The associated identifier of… | |
| Modificada | Media (5.4) | 0.34% | — | Bagesoft Bagecms | 6/7/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module. | |
| Modificada | Crítica (9.8) | 0.75% | — | Bluecms Project Bluecms | 30/5/2023 | 17/6/2026 | BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php. | |
| Modificada | Alta (8.8) | 51% | 💥 PoC | Dedecms | 27/5/2023 | 17/6/2026 | A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.38% | — | Thecosy Icecms | 25/5/2023 | 17/6/2026 | IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS). |