Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)71%💥 ExploitIncomcms Project Incomcms7/12/202017/6/2026
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.
ModificadaCrítica (9.8)1.9%—Victor CMS Project Victor CMS2/12/202017/6/2026
The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.
ModificadaCrítica (9.8)1.9%—Ucms Project Ucms30/11/202017/6/2026
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
ModificadaAlta (8.8)2.5%—Horizontcms Project Horizontcms16/11/202017/6/2026
An unrestricted file upload issue in HorizontCMS 1.0.0-beta allows an authenticated remote attacker to upload PHP code through a zip file by uploading a theme, and executing the PHP file via an HTTP GET request to /themes/<php_file_name>
ModificadaAlta (8.8)73%💥 ExploitFlexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or…
ModificadaAlta (8.1)1.8%—Flexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>…
ModificadaAlta (8.8)18%💥 ExploitHorizontcms Project Horizontcms5/11/202017/6/2026
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access to the FileManager) to upload and execute arbitrary PHP code by uploading a PHP payload, and then using the FileManager's rename function to provide the payload (which will receive a random name on…
ModificadaAlta (7.5)1.2%—Victor CMS Project Victor CMS27/10/202017/6/2026
A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.
ModificadaCrítica (9.8)8.6%—Ucms Project Ucms23/10/202017/6/2026
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
ModificadaMedia (4.8)1.7%—Soycms Project Soycms17/9/202017/6/2026
SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) from a known vulnerability. This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage.
ModificadaCrítica (9.6)1.2%—SOY CMS Project SOY CMSSOY Inquiry Project SOY Inquiry17/9/202017/6/2026
The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the administrator loads a specially crafted webpage.…
ModificadaMedia (5.3)0.95%—Ucms Project Ucms4/9/202017/6/2026
An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly accessing the website built by UCMS.
ModificadaMedia (6.1)15%💥 ExploitMara CMS Project Mara CMS30/8/202017/6/2026
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
ModificadaMedia (6.1)0.81%—Kandnconcepts Club CMS Project Kandnconcepts Club CMS27/8/202017/6/2026
KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
ModificadaCrítica (9.8)1.6%—Kandnconcepts Club CMS Project Kandnconcepts Club CMS27/8/202017/6/2026
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
ModificadaAlta (7.2)1.4%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_content'] is file content, there is no filter function for security. A remote authenticated admin user can exploit this vulnerability to get a webshell.
ModificadaMedia (4.9)0.92%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
ModificadaAlta (8.8)0.51%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
ModificadaMedia (5.9)0.74%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table.
ModificadaMedia (4.8)0.86%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
ModificadaAlta (8.1)0.44%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
ModificadaMedia (4.8)0.88%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
ModificadaMedia (4.8)0.68%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.
ModificadaMedia (4.8)0.85%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
ModificadaMedia (4.8)0.85%—Dbhcms Project Dbhcms24/8/202017/6/2026
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menus.edit.php line 83 and in dbhcms\mod\mod.menus.view.php line 111, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
Orbitaley — Vulnerabilidades