Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.0%—Flamecms Project Flamecms14/9/201917/6/2026
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
ModificadaMedia (5.4)0.65%—Frog CMS Project Frog CMS22/7/201917/6/2026
Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecting to another phishing site, Executing browser exploits. The component is: Snippets.
ModificadaAlta (8.8)1.2%—Ucms Project Ucms21/5/201917/6/2026
sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.
ModificadaAlta (8.8)1.8%—Mkcms Project Mkcms18/4/201917/6/2026
MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which triggers e-mail transmission with the password, as demonstrated by 123456.
ModificadaAlta (8.8)0.61%—Mkcms Project Mkcms11/4/201917/6/2026
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.
ModificadaCrítica (9.8)1.5%—Mkcms Project Mkcms2/4/201917/6/2026
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
ModificadaCrítica (9.8)1.5%—Bluecms Project Bluecms28/3/201917/6/2026
A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes.
ModificadaMedia (6.1)1.5%—Kinagacms Project Kinagacms27/3/201917/6/2026
Cross-site scripting vulnerability in KinagaCMS versions prior to 6.5 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (8.8)0.65%—Njiandan-cms Project Njiandan-cms7/3/201917/6/2026
njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator.
ModificadaMedia (6.1)0.83%—Ucms Project Ucms7/3/201917/6/2026
An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.
ModificadaAlta (8.8)2.7%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.
ModificadaAlta (7.2)2.7%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.
ModificadaAlta (7.2)1.3%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java.
ModificadaAlta (8.8)2.6%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command.
ModificadaAlta (7.2)2.7%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI.
ModificadaAlta (8.8)2.7%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/upload URI.
ModificadaMedia (6.5)1.4%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name parameter). This is related to the save function…
ModificadaMedia (4.3)1.4%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java.
ModificadaAlta (8.8)2.7%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/editUploadImage URI.
ModificadaAlta (8.8)2.7%—Ofcms Project Ofcms6/3/201917/6/2026
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadImage URI.
ModificadaCrítica (9.8)1.5%—Bluecms Project Bluecms6/3/201917/6/2026
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
ModificadaMedia (4.8)0.64%—Dhcms Project Dhcms3/3/201917/6/2026
DhCms through 2017-09-18 has admin.php?r=admin/Index/index XSS.
ModificadaMedia (6.1)0.83%—Wtcms Project Wtcms18/2/201917/6/2026
An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code).
ModificadaAlta (8.8)0.61%—Wtcms Project Wtcms18/2/201917/6/2026
An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF.
ModificadaAlta (7.5)1.8%—Wtcms Project Wtcms18/2/201917/6/2026
An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image.