Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

595 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in usersController.php.
ModificadaCrítica (9.8)1.3%—Exponentcms Exponent CMS31/12/202017/6/2026
Exponent CMS before 2.6.0 has improper input validation in storeController.php.
ModificadaMedia (5.3)1.1%—Boltcms Bolt30/12/202017/6/2026
Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance.
ModificadaAlta (8.8)1.2%—Dotcms30/12/202017/6/2026
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated…
ModificadaMedia (4.8)0.62%—Dotcms21/12/20209/7/2026
DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.
ModificadaMedia (6.5)0.44%—Pbootcms30/11/202017/6/2026
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
ModificadaAlta (8.8)2.5%—Horizontcms Project Horizontcms16/11/202017/6/2026
An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>
ModificadaAlta (8.8)73%💥 ExploitFlexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or…
ModificadaAlta (8.1)1.8%—Flexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>…
ModificadaAlta (8.8)18%💥 ExploitHorizontcms Project Horizontcms5/11/202017/6/2026
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on…
ModificadaMedia (6.1)2.0%—Boltcms Bolt8/6/202017/6/2026
In Bolt CMS before version 3.7.1, the filename of uploaded files was vulnerable to stored XSS. It is not possible to inject javascript code in the file name when creating/uploading the file. But, once created/uploaded, it can be renamed to inject the payload in it. Additionally, the measures to prevent renaming the…
ModificadaMedia (4.3)1.8%💥 PoCBoltcms Bolt8/6/202017/6/2026
Bolt CMS before version 3.7.1 lacked CSRF protection in the preview generating endpoint. Previews are intended to be generated by the admins, developers, chief-editors, and editors, who are authorized to create content in the application. But due to lack of proper CSRF protection, unauthorized users could generate a…
ModificadaCrítica (9.8)73%💥 ExploitCraftcms Craft CMS4/3/202017/6/2026
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
ModificadaCrítica (9.8)1.8%—Pbootcms2/3/202017/6/2026
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.
ModificadaCrítica (9.8)1.8%—Pbootcms2/3/202017/6/2026
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
ModificadaCrítica (9.8)95%—Dotcms5/2/202017/6/2026
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into…
ModificadaMedia (6.1)3.7%💥 ExploitCraftcms Craft CMS31/12/201917/6/2026
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
ModificadaMedia (6.1)1.8%💥 ExploitBoltcms Bolt31/12/201917/6/2026
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and CVE-2018-19933.
ModificadaMedia (6.1)0.70%—Boltcms Bolt29/12/201917/6/2026
Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profiler page. NOTE: this is disputed because profiling was never intended for use in production. This is related to CVE-2018-12040
ModificadaCrítica (9.8)1.8%—Craftcms Craft CMS24/10/201917/6/2026
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
ModificadaMedia (6.1)0.84%—Craftcms Craft CMS11/10/201917/6/2026
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
ModificadaMedia (4.8)0.65%—Pbootcms10/10/201917/6/2026
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
ModificadaAlta (7.2)2.1%—Otcms9/10/201917/6/2026
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulation. Therefore, the attacker can create a .php file.
Orbitaley — Vulnerabilidades