Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 71% | 💥 Exploit | Incomcms Project Incomcms | 7/12/2020 | 17/6/2026 | IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server. | |
| Modificada | Crítica (9.8) | 1.9% | — | Victor CMS Project Victor CMS | 2/12/2020 | 17/6/2026 | The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page. | |
| Modificada | Crítica (9.8) | 1.9% | — | Ucms Project Ucms | 30/11/2020 | 17/6/2026 | File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. | |
| Modificada | Alta (8.8) | 2.5% | — | Horizontcms Project Horizontcms | 16/11/2020 | 17/6/2026 | An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name> | |
| Modificada | Alta (8.8) | 73% | 💥 Exploit | Flexdotnetcms Project Flexdotnetcms | 12/11/2020 | 17/6/2026 | An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or… | |
| Modificada | Alta (8.1) | 1.8% | — | Flexdotnetcms Project Flexdotnetcms | 12/11/2020 | 17/6/2026 | Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>… | |
| Modificada | Alta (8.8) | 18% | 💥 Exploit | Horizontcms Project Horizontcms | 5/11/2020 | 17/6/2026 | An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on… | |
| Modificada | Alta (7.5) | 1.2% | — | Victor CMS Project Victor CMS | 27/10/2020 | 17/6/2026 | A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database. | |
| Modificada | Crítica (9.8) | 8.6% | — | Ucms Project Ucms | 23/10/2020 | 17/6/2026 | An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server. | |
| Modificada | Media (4.8) | 1.7% | — | Soycms Project Soycms | 17/9/2020 | 17/6/2026 | SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) from a known vulnerability. This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage. | |
| Modificada | Crítica (9.6) | 1.2% | — | SOY CMS Project SOY CMSSOY Inquiry Project SOY Inquiry | 17/9/2020 | 17/6/2026 | The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the administrator loads a specially crafted webpage.… | |
| Modificada | Media (5.3) | 0.95% | — | Ucms Project Ucms | 4/9/2020 | 17/6/2026 | An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly accessing the website built by UCMS. | |
| Modificada | Media (6.1) | 15% | 💥 Exploit | Mara CMS Project Mara CMS | 30/8/2020 | 17/6/2026 | Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters. | |
| Modificada | Media (6.1) | 0.81% | — | Kandnconcepts Club CMS Project Kandnconcepts Club CMS | 27/8/2020 | 17/6/2026 | KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter. | |
| Modificada | Crítica (9.8) | 1.6% | — | Kandnconcepts Club CMS Project Kandnconcepts Club CMS | 27/8/2020 | 17/6/2026 | KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter. | |
| Modificada | Alta (7.2) | 1.4% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_content'] is file content, there is no filter function for security. A remote authenticated admin user can exploit this vulnerability to get a webshell. | |
| Modificada | Media (4.9) | 0.92% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content. | |
| Modificada | Alta (8.8) | 0.51% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user. | |
| Modificada | Media (5.9) | 0.74% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table. | |
| Modificada | Media (4.8) | 0.86% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users. | |
| Modificada | Alta (8.1) | 0.44% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu. | |
| Modificada | Media (4.8) | 0.88% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users. | |
| Modificada | Media (4.8) | 0.68% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119. | |
| Modificada | Media (4.8) | 0.85% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerability to hijack other users. | |
| Modificada | Media (4.8) | 0.85% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menus.edit.php line 83 and in dbhcms\mod\mod.menus.view.php line 111, A remote authenticated with admin user can exploit this vulnerability to hijack other users. |