Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.99%—Thinkphp-zcms Project Thinkphp-zcms26/8/202117/6/2026
thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
ModificadaAlta (7.5)1.0%—Joyplus-cms Project Joyplus-cms18/8/202117/6/2026
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
ModificadaAlta (7.5)1.3%—Find A Place Ljcms Project Find A Place Ljcms18/8/202117/6/2026
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
ModificadaMedia (6.8)0.48%—Bycms Project Bycms12/8/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html.
ModificadaMedia (4.8)0.53%—Bycms Project Bycms12/8/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document.php.
ModificadaMedia (6.8)0.48%—Bycms Project Bycms12/8/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
ModificadaAlta (8.8)1.8%—Newsone CMS Project Newsone CMS11/8/202117/6/2026
An arbitrary file upload in the <input type="file" name="user_image"> component of NewsOne CMS v1.1.0 allows attackers to webshell and execute arbitrary commands.
ModificadaMedia (6.5)0.44%—Wagecms Project Wage-cms6/8/202117/6/2026
A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.
ModificadaMedia (5.4)0.59%—Engineercms Project Engineercms30/7/202117/6/2026
engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user list page. When viewing this page, the JavaScript code will be executed in the user's browser.
ModificadaMedia (5.3)0.93%—Ucms Project Ucms23/7/202117/6/2026
UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.
ModificadaCrítica (9.8)1.9%—Victor CMS Project Victor CMS23/7/202117/6/2026
Arbitrary file upload vulnerability in Victor CMS v 1.0 allows attackers to execute arbitrary code via the file upload to \CMSsite-master\admin\includes\admin_add_post.php.
ModificadaCrítica (9.8)1.5%—Fantastic Blog CMS Project Fantastic Blog CMS22/7/202117/6/2026
SQL injection vulnerability in SourceCodester Fantastic Blog CMS v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to category.php.
ModificadaAlta (7.5)1.1%—Wayang-cms Project Wayang-cms14/7/202117/6/2026
A SQL injection vulnerability in wy_controlls/wy_side_visitor.php of Wayang-CMS v1.0 allows attackers to obtain sensitive database information.
ModificadaMedia (6.1)0.66%—Wayang-cms Project Wayang-cms14/7/202117/6/2026
A cross site scripting (XSS) vulnerability in index.php of Wayang-CMS v1.0 allows attackers to execute arbitrary web scripts or HTML via a constructed payload created by adding the X-Forwarded-For field to the header.
ModificadaCrítica (9.8)2.0%—Artware CMS Project Artware CMS7/7/202117/6/2026
ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly.
ModificadaAlta (8.6)1.7%—Webport CMS Project Webport CMS28/6/202117/6/2026
Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.
ModificadaMedia (6.1)0.81%—Gris CMS Project Gris CMS24/5/202117/6/2026
An issue was discovered in Gris CMS v0.1. There is a Persistent XSS vulnerability which allows remote attackers to inject arbitrary web script or HTML via admin/dashboard.
ModificadaCrítica (9.8)1.7%—Hongcms Project Hongcms18/5/202117/6/2026
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."
ModificadaCrítica (9.8)1.3%—Articlecms Project Articlecms13/5/202117/6/2026
A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
ModificadaCrítica (9.8)1.3%—Articlecms Project Articlecms13/5/202117/6/2026
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.
ModificadaMedia (5.3)1.2%—Dhcms Project Dhcms12/5/202117/6/2026
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.
ModificadaMedia (6.1)0.85%—Dhcms Project Dhcms12/5/202117/6/2026
A Cross SIte Scripting (XSS) vulnerability exists in Dhcms 2017-09-18 in guestbook via the message board, which could let a remote malicious user execute arbitrary code.
ModificadaCrítica (9.8)2.4%—Lightcms Project Lightcms15/4/202117/6/2026
LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.
ModificadaAlta (7.5)1.3%—Flycms Project Flycms1/4/202117/6/2026
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.
ModificadaMedia (5.4)7.2%💥 ExploitLightcms Project Lightcms24/2/202117/6/2026
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Title field to /admin/SensitiveWords.