Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.61% | — | Thecosy Icecms | 25/5/2023 | 17/6/2026 | IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information. | |
| Modificada | Media (5.4) | 0.45% | — | Dedecms | 19/5/2023 | 17/6/2026 | DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian' | |
| Modificada | Media (6.1) | 0.52% | — | 5none Nonecms | 8/5/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature. | |
| Modificada | Alta (8.8) | 0.88% | — | Dedecms | 29/4/2023 | 17/6/2026 | A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uploads/dede/config.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.74% | — | Mlecms | 29/4/2023 | 17/6/2026 | A vulnerability was found in MLECMS 3.0. It has been rated as critical. This issue affects the function get_url in the library /upload/inc/lib/admin of the file upload\inc\include\common.func.php. The manipulation of the argument $_SERVER['REQUEST_URI'] leads to sql injection. The attack may be initiated remotely. The… | |
| Modificada | Media (5.3) | 0.73% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets. | |
| Modificada | Media (5.4) | 0.39% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized. | |
| Modificada | Media (5.4) | 0.64% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names. | |
| Modificada | Media (5.4) | 0.58% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter. | |
| Modificada | Media (5.4) | 0.54% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files. | |
| Modificada | Media (6.1) | 0.64% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized. | |
| Modificada | Media (5.4) | 0.63% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search. | |
| Modificada | Baja (3.3) | 0.76% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section. | |
| Modificada | Media (5.3) | 0.59% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies. | |
| Modificada | Media (5.4) | 0.54% | — | Concretecms Concrete CMS | 28/4/2023 | 17/6/2026 | Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name. | |
| Modificada | Alta (7.5) | 1.2% | — | Dedecms | 27/4/2023 | 17/6/2026 | An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal. | |
| Modificada | Alta (7.2) | 0.79% | — | Dedecms | 17/4/2023 | 17/6/2026 | DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php. | |
| Modificada | Media (5.3) | 2.4% | 💥 Exploit | Dedecms | 14/4/2023 | 17/6/2026 | A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/select_templets.php. The manipulation leads to path traversal: '..\filedir'. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.97% | — | Dedecms | 14/4/2023 | 17/6/2026 | A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Alta (7.2) | 1.3% | — | Kitesky Kitecms | 4/4/2023 | 17/6/2026 | File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function. | |
| Modificada | Crítica (9.8) | 1.3% | — | Kitesky Kitecms | 4/4/2023 | 17/6/2026 | Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type. | |
| Modificada | Media (6.1) | 0.56% | — | Kitesky Kitecms | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Kitesky Kitecms | 4/4/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter. | |
| Modificada | Alta (7.2) | 1.3% | — | Dedecms | 16/3/2023 | 17/6/2026 | SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint. | |
| Modificada | Alta (7.2) | 1.3% | — | Dedecms | 16/3/2023 | 17/6/2026 | SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint. |