Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Apostrophecms Sanitize-html | 30/8/2022 | 17/6/2026 | The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal. | |
| Modificada | Crítica (9.8) | 15% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | Bluecms 1.6 has SQL injection in line 132 of admin/area.php | |
| Modificada | Crítica (9.8) | 0.88% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | BlueCMS 1.6 has SQL injection in line 55 of admin/model.php | |
| Modificada | Crítica (9.8) | 0.90% | — | Bluecms Project Bluecms | 23/8/2022 | 17/6/2026 | BlueCMS 1.6 has SQL injection in line 132 of admin/article.php | |
| Modificada | Alta (7.2) | 2.1% | — | Dedecms | 17/8/2022 | 17/6/2026 | DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php. | |
| Modificada | Alta (7.2) | 2.3% | — | Dedebiz Dedecmsv6 | 17/8/2022 | 17/6/2026 | DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php. | |
| Modificada | Crítica (9.8) | 2.6% | — | Dedecms | 17/8/2022 | 17/6/2026 | DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php. | |
| Modificada | Media (5.4) | 0.59% | — | Bigtreecms Bigtree CMS | 3/8/2022 | 17/6/2026 | BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Crítica (9.8) | 25% | — | Dedecms | 29/7/2022 | 17/6/2026 | DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php. | |
| Modificada | Media (6.1) | 1.00% | — | Concretecms Concrete CMS | 24/6/2022 | 17/6/2026 | XSS in /dashboard/blocks/stacks/view_details/ - old browsers only. When using an older browser with built-in XSS protection disabled, insufficient sanitation where built urls are outputted can be exploited for Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 to allow XSS. This cannot be exploited in… | |
| Modificada | Media (6.1) | 0.90% | — | Concretecms Concrete CMS | 24/6/2022 | 17/6/2026 | XSS in /dashboard/reports/logs/view - old browsers only. When using Internet Explorer with the XSS protection disabled, insufficient sanitation where built urls are outputted can be exploited for Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2. This cannot be exploited in modern-day web browsers due to… | |
| Modificada | Media (6.1) | 0.90% | — | Concretecms Concrete CMS | 24/6/2022 | 17/6/2026 | Title for CVE: XSS in /dashboard/system/express/entities/forms/save_control/[GUID]: old browsers only.Description: When using Internet Explorer with the XSS protection disabled, editing a form control in an express entities form for Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 can allow XSS. This… | |
| Modificada | Crítica (9.1) | 2.1% | — | Concretecms Concrete CMS | 24/6/2022 | 17/6/2026 | Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrary File Delete exploit. This was remediated by sanitizing /index.php/ccm/system/file/upload to ensure Concrete doesn’t allow traversal and by changing… | |
| Modificada | Crítica (9.8) | 1.8% | — | Concretecms Concrete CMS | 24/6/2022 | 17/6/2026 | Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from those zip files which could lead to an RCE. Fixed by enforcing ‘concrete_secure’ instead of ‘concrete’. Concrete now only makes requests over https even a request comes in via http. Concrete CMS… | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 2/6/2022 | 17/6/2026 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_sidebar.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 2/6/2022 | 17/6/2026 | elitecms 1.01 is vulnerable to SQL Injection via admin/edit_sidebar.php?page=2&sidebar= | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 2/6/2022 | 17/6/2026 | elitecms v1.01 is vulnerable to SQL Injection via /admin/add_sidebar.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 2/6/2022 | 17/6/2026 | elitecms 1.01 is vulnerable to SQL Injection via /admin/add_post.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 2/6/2022 | 17/6/2026 | elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 2/6/2022 | 17/6/2026 | elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=. | |
| Modificada | Crítica (9.8) | 17% | — | Elitecms Elite CMS | 2/6/2022 | 17/6/2026 | elitecms 1.0.1 is vulnerable to Arbitrary code execution via admin/manage_uploads.php. | |
| Modificada | Media (6.5) | 1.1% | — | Elitecms Elite CMS | 2/6/2022 | 17/6/2026 | elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=. | |
| Modificada | Media (6.5) | 1.1% | — | Dedecms | 26/5/2022 | 17/6/2026 | DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter. | |
| Modificada | Crítica (9.8) | 18% | — | Ionizecms Ionize | 12/5/2022 | 17/6/2026 | IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Ionizecms Ionize | 12/5/2022 | 17/6/2026 | IonizeCMS v1.0.8.1 was discovered to contain a SQL injection vulnerability via the id_page parameter in application/models/article_model.php. |