Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

595 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.52%—Otcms9/10/201917/6/2026
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated by superadmin.
ModificadaMedia (6.5)0.52%—Wtcms Project Wtcms23/9/201917/6/2026
WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS.
ModificadaMedia (6.1)0.86%—Boltcms Bolt23/8/201917/6/2026
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
ModificadaMedia (6.1)0.86%—Boltcms Bolt23/8/201917/6/2026
Bolt before 3.6.10 has XSS via an image's alt or title field.
ModificadaMedia (6.1)0.86%—Boltcms Bolt23/8/201917/6/2026
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
ModificadaMedia (5.3)9.4%💥 ExploitCraftcms Craft CMS26/7/201917/6/2026
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
ModificadaMedia (6.1)0.85%—Otcms19/7/201917/6/2026
OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.
ModificadaAlta (7.2)1.3%—Dotcms18/6/201917/6/2026
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.
ModificadaMedia (6.1)0.94%—Craftcms Craft CMS18/6/201917/6/2026
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
ModificadaCrítica (9.8)2.1%—Exponentcms Exponent CMS24/5/201917/6/2026
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.
ModificadaCrítica (9.8)1.8%—Exponentcms Exponent CMS24/5/201917/6/2026
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.
ModificadaMedia (4.9)1.3%—Dotcms23/5/201917/6/2026
dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerability is caused by the insecure extraction of a ZIP archive.
ModificadaCrítica (9.8)2.1%—Exponentcms Exponent CMS23/5/201917/6/2026
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.
ModificadaCrítica (9.8)1.8%—Exponentcms Exponent CMS23/5/201917/6/2026
Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.
ModificadaMedia (6.1)1.00%—Dotcms14/5/201917/6/2026
/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.
ModificadaAlta (8.8)4.5%💥 ExploitBoltcms Bolt5/4/201917/6/2026
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to execute arbitrary code by uploading a JavaScript file to include executable extensions in the file/edit/config/config.yml configuration file.
ModificadaAlta (8.8)2.8%—Moxa Softcms21/3/201917/6/2026
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
ModificadaAlta (8.8)2.8%—Moxa Softcms21/3/201917/6/2026
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
ModificadaAlta (8.8)2.7%—Boltcms Bolt7/3/201917/6/2026
Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitrary PHP code by renaming a previously uploaded file to have a .php extension.
ModificadaMedia (6.1)3.7%💥 ExploitDotcms7/3/201917/6/2026
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
ModificadaMedia (6.1)0.83%—Wtcms Project Wtcms18/2/201917/6/2026
An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).
ModificadaAlta (8.8)0.61%—Wtcms Project Wtcms18/2/201917/6/2026
An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
ModificadaAlta (7.5)1.8%—Wtcms Project Wtcms18/2/201917/6/2026
An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image.
ModificadaCrítica (9.8)2.3%—Wtcms Project Wtcms18/2/201917/6/2026
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type: image/gif" header.
ModificadaAlta (7.2)1.3%—Pbootcms17/2/201917/6/2026
A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php.
Orbitaley — Vulnerabilidades