Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.86% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_name'] parameter, A remote authenticated with admin user can exploit this vulnerability to hijack other users. | |
| Modificada | Media (6.1) | 0.89% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote unauthenticated attacker can exploit this vulnerability to hijack other users. | |
| Modificada | Media (6.1) | 0.70% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.php line 107, | |
| Modificada | Alta (7.5) | 1.5% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news/ext.news.be.php, A remote unauthenticated attacker can exploit this vulnerability to get path information. | |
| Modificada | Media (5.3) | 1.7% | — | Dbhcms Project Dbhcms | 24/8/2020 | 17/6/2026 | DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information. | |
| Modificada | Media (6.1) | 1.2% | — | Galileo CMS Project Galileo CMS | 14/8/2020 | 17/6/2026 | There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field). | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Victor CMS Project Victor CMS | 7/7/2020 | 17/6/2026 | Victor CMS through 2019-02-28 allows XSS via the register.php user_firstname or user_lastname field. | |
| Modificada | Media (6.1) | 0.87% | — | Victorcms Project Victorcms | 22/6/2020 | 17/6/2026 | Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter. | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Polarbear CMS Project Polarbear CMS | 11/2/2020 | 16/6/2026 | A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code. | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | Lotus Core CMS Project Lotus Core CMS | 5/2/2020 | 17/6/2026 | Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php page_slug parameter. | |
| Modificada | Crítica (9.8) | 2.7% | — | BSS Continuity CMS Project BSS Continuty CMS | 9/1/2020 | 17/6/2026 | BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability | |
| Modificada | Crítica (9.8) | 4.0% | — | BSS Continuity CMS Project BSS Continuty CMS | 9/1/2020 | 17/6/2026 | BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload | |
| Modificada | Alta (7.5) | 1.8% | — | BSS Continuity CMS Project BSS Continuty CMS | 9/1/2020 | 17/6/2026 | BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability | |
| Modificada | Media (6.1) | 1.0% | — | Hongcms Project Hongcms | 16/10/2019 | 17/6/2026 | HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Hongcms Project Hongcms | 16/10/2019 | 17/6/2026 | HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Hongcms Project Hongcms | 16/10/2019 | 17/6/2026 | HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Hongcms Project Hongcms | 16/10/2019 | 17/6/2026 | HongCMS 3.0.0 has XSS via the install/index.php dbname parameter. | |
| Modificada | Media (6.1) | 1.0% | — | Hongcms Project Hongcms | 16/10/2019 | 17/6/2026 | HongCMS 3.0.0 has XSS via the install/index.php servername parameter. | |
| Modificada | Media (6.5) | 0.44% | — | Landing-cms Project Landing-cms | 12/10/2019 | 17/6/2026 | An issue was discovered in Landing-CMS 0.0.6. There is a CSRF vulnerability that can change the admin's password via the password/ URI, | |
| Modificada | Crítica (9.8) | 1.4% | — | Adhouma CMS Project Adhouma CMS | 10/10/2019 | 17/6/2026 | Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Joyplus-cms Project Joyplus-cms | 4/10/2019 | 17/6/2026 | joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal. | |
| Modificada | Media (6.1) | 0.82% | — | Kkcms Project Kkcms | 27/9/2019 | 17/6/2026 | kkcms 1.3 has jx.php?url= XSS. | |
| Modificada | Media (6.5) | 1.1% | — | Hongcms Project Hongcms | 25/9/2019 | 17/6/2026 | HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.) | |
| Modificada | Media (6.5) | 0.52% | — | Wtcms Project Wtcms | 23/9/2019 | 17/6/2026 | WTCMS 1.0 allows index.php?g=admin&m=index&a=index CSRF with resultant XSS. | |
| Modificada | Alta (8.8) | 0.60% | — | Kkcms Project Kkcms | 23/9/2019 | 17/6/2026 | kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php. |