Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.52% | — | Otcms | 9/10/2019 | 17/6/2026 | OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin. | |
| Modificada | Media (6.5) | 0.52% | — | Wtcms Project Wtcms | 23/9/2019 | 17/6/2026 | WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS. | |
| Modificada | Media (6.1) | 0.86% | — | Boltcms Bolt | 23/8/2019 | 17/6/2026 | Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php. | |
| Modificada | Media (6.1) | 0.86% | — | Boltcms Bolt | 23/8/2019 | 17/6/2026 | Bolt before 3.6.10 has XSS via an image's alt or title field. | |
| Modificada | Media (6.1) | 0.86% | — | Boltcms Bolt | 23/8/2019 | 17/6/2026 | Bolt before 3.6.10 has XSS via a title that is mishandled in the system log. | |
| Modificada | Media (5.3) | 9.4% | 💥 Exploit | Craftcms Craft CMS | 26/7/2019 | 17/6/2026 | In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public. | |
| Modificada | Media (6.1) | 0.85% | — | Otcms | 19/7/2019 | 17/6/2026 | OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request. | |
| Modificada | Alta (7.2) | 1.3% | — | Dotcms | 18/6/2019 | 17/6/2026 | dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp. | |
| Modificada | Media (6.1) | 0.94% | — | Craftcms Craft CMS | 18/6/2019 | 17/6/2026 | Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. | |
| Modificada | Crítica (9.8) | 2.1% | — | Exponentcms Exponent CMS | 24/5/2019 | 17/6/2026 | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags. | |
| Modificada | Crítica (9.8) | 1.8% | — | Exponentcms Exponent CMS | 24/5/2019 | 17/6/2026 | Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php. | |
| Modificada | Media (4.9) | 1.3% | — | Dotcms | 23/5/2019 | 17/6/2026 | dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerability is caused by the insecure extraction of a ZIP archive. | |
| Modificada | Crítica (9.8) | 2.1% | — | Exponentcms Exponent CMS | 23/5/2019 | 17/6/2026 | Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats. | |
| Modificada | Crítica (9.8) | 1.8% | — | Exponentcms Exponent CMS | 23/5/2019 | 17/6/2026 | Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php. | |
| Modificada | Media (6.1) | 1.00% | — | Dotcms | 14/5/2019 | 17/6/2026 | /servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection. | |
| Modificada | Alta (8.8) | 4.5% | 💥 Exploit | Boltcms Bolt | 5/4/2019 | 17/6/2026 | Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file. | |
| Modificada | Alta (8.8) | 2.8% | — | Moxa Softcms | 21/3/2019 | 17/6/2026 | Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability. | |
| Modificada | Alta (8.8) | 2.8% | — | Moxa Softcms | 21/3/2019 | 17/6/2026 | Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability. | |
| Modificada | Alta (8.8) | 2.7% | — | Boltcms Bolt | 7/3/2019 | 17/6/2026 | Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension. | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Dotcms | 7/3/2019 | 17/6/2026 | dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter. | |
| Modificada | Media (6.1) | 0.83% | — | Wtcms Project Wtcms | 18/2/2019 | 17/6/2026 | An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code). | |
| Modificada | Alta (8.8) | 0.61% | — | Wtcms Project Wtcms | 18/2/2019 | 17/6/2026 | An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF. | |
| Modificada | Alta (7.5) | 1.8% | — | Wtcms Project Wtcms | 18/2/2019 | 17/6/2026 | An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image. | |
| Modificada | Crítica (9.8) | 2.3% | — | Wtcms Project Wtcms | 18/2/2019 | 17/6/2026 | An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type: image/gif" header. | |
| Modificada | Alta (7.2) | 1.3% | — | Pbootcms | 17/2/2019 | 17/6/2026 | A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php. |