Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

824 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.61%—Thecosy Icecms25/5/202317/6/2026
IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information.
ModificadaMedia (5.4)0.45%—Dedecms19/5/202317/6/2026
DedeCMS up to v5.7.108 is vulnerable to XSS in sys_info.php via parameters 'edit___cfg_powerby' and 'edit___cfg_beian'
ModificadaMedia (6.1)0.52%—5none Nonecms8/5/202317/6/2026
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature.
ModificadaAlta (8.8)0.88%—Dedecms29/4/202317/6/2026
A vulnerability was found in DedeCMS 5.7.106 and classified as critical. Affected by this issue is the function UpDateMemberModCache of the file uploads/dede/config.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)0.74%—Mlecms29/4/202317/6/2026
A vulnerability was found in MLECMS 3.0. It has been rated as critical. This issue affects the function get_url in the library /upload/inc/lib/admin of the file upload\inc\include\common.func.php. The manipulation of the argument $_SERVER['REQUEST_URI'] leads to sql injection. The attack may be initiated remotely. The…
ModificadaMedia (5.3)0.73%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) before 9.1 did not have a rate limit for password resets.
ModificadaMedia (5.4)0.39%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) before 9.1 is vulnerable to stored XSS in RSS Displayer via the href attribute because the link element input was not sanitized.
ModificadaMedia (5.4)0.64%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) versions 8.5.12 and below, 9.0.0 through 9.0.2 is vulnerable to Stored XSS in uploaded file and folder names.
ModificadaMedia (5.4)0.58%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to stored XSS on API Integrations via the name parameter.
ModificadaMedia (5.4)0.54%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Tags on uploaded files.
ModificadaMedia (6.1)0.64%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) versions 8.5.12 and below, and versions 9.0 through 9.1.3 is vulnerable to Reflected XSS on the Reply form because msgID was not sanitized.
ModificadaMedia (5.4)0.63%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search.
ModificadaBaja (3.3)0.76%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.
ModificadaMedia (5.3)0.59%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 does not have Secure and HTTP only attributes set for ccmPoll cookies.
ModificadaMedia (5.4)0.54%—Concretecms Concrete CMS28/4/202317/6/2026
Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS via a container name.
ModificadaAlta (7.5)1.2%—Dedecms27/4/202317/6/2026
An issue in the component /dialog/select_media.php of DedeCMS v5.7.107 allows attackers to execute a directory traversal.
ModificadaAlta (7.2)0.79%—Dedecms17/4/202317/6/2026
DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php.
ModificadaMedia (5.3)2.4%💥 ExploitDedecms14/4/202317/6/2026
A vulnerability was found in DedeCMS 5.7.87. It has been rated as problematic. Affected by this issue is some unknown functionality of the file uploads/include/dialog/select_templets.php. The manipulation leads to path traversal: '..\filedir'. The attack may be launched remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.97%—Dedecms14/4/202317/6/2026
A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaAlta (7.2)1.3%—Kitesky Kitecms4/4/202317/6/2026
File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.
ModificadaCrítica (9.8)1.3%—Kitesky Kitecms4/4/202317/6/2026
Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.
ModificadaMedia (6.1)0.56%—Kitesky Kitecms4/4/202317/6/2026
Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter.
ModificadaMedia (6.1)0.56%—Kitesky Kitecms4/4/202317/6/2026
Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter.
ModificadaAlta (7.2)1.3%—Dedecms16/3/202317/6/2026
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dedestory_catalog.php endpoint.
ModificadaAlta (7.2)1.3%—Dedecms16/3/202317/6/2026
SQL injection vulnerability found in DedeCMS v.5.7.106 allows a remote attacker to execute arbitrary code via the rank_* parameter in the /dede/group_store.php endpoint.