Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.0% | — | Flamecms Project Flamecms | 14/9/2019 | 17/6/2026 | FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. | |
| Modificada | Media (5.4) | 0.65% | — | Frog CMS Project Frog CMS | 22/7/2019 | 17/6/2026 | Frog CMS 1.1 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing, Alert pop-up on page, Redirecting to another phishing site, Executing browser exploits. The component is: Snippets. | |
| Modificada | Alta (8.8) | 1.2% | — | Ucms Project Ucms | 21/5/2019 | 17/6/2026 | sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter. | |
| Modificada | Alta (8.8) | 1.8% | — | Mkcms Project Mkcms | 18/4/2019 | 17/6/2026 | MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which triggers e-mail transmission with the password, as demonstrated by 123456. | |
| Modificada | Alta (8.8) | 0.61% | — | Mkcms Project Mkcms | 11/4/2019 | 17/6/2026 | MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mkcms Project Mkcms | 2/4/2019 | 17/6/2026 | MKCMS V5.0 has SQL injection via the bplay.php play parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Bluecms Project Bluecms | 28/3/2019 | 17/6/2026 | A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resulting in injection around the escape of magic quotes. | |
| Modificada | Media (6.1) | 1.5% | — | Kinagacms Project Kinagacms | 27/3/2019 | 17/6/2026 | Cross-site scripting vulnerability in KinagaCMS versions prior to 6.5 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.65% | — | Njiandan-cms Project Njiandan-cms | 7/3/2019 | 17/6/2026 | njiandan-cms through 2013-05-23 has index.php/admin/user_new CSRF to add an administrator. | |
| Modificada | Media (6.1) | 0.83% | — | Ucms Project Ucms | 7/3/2019 | 17/6/2026 | An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request. | |
| Modificada | Alta (8.8) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI. | |
| Modificada | Alta (7.2) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI. | |
| Modificada | Alta (7.2) | 1.3% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. | |
| Modificada | Alta (8.8) | 2.6% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command. | |
| Modificada | Alta (7.2) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI. | |
| Modificada | Alta (8.8) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/upload URI. | |
| Modificada | Media (6.5) | 1.4% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name parameter). This is related to the save function… | |
| Modificada | Media (4.3) | 1.4% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java. | |
| Modificada | Alta (8.8) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/editUploadImage URI. | |
| Modificada | Alta (8.8) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadImage URI. | |
| Modificada | Crítica (9.8) | 1.5% | — | Bluecms Project Bluecms | 6/3/2019 | 17/6/2026 | BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. | |
| Modificada | Media (4.8) | 0.64% | — | Dhcms Project Dhcms | 3/3/2019 | 17/6/2026 | DhCms through 2017-09-18 has admin.php?r=admin/Index/index XSS. | |
| Modificada | Media (6.1) | 0.83% | — | Wtcms Project Wtcms | 18/2/2019 | 17/6/2026 | An issue was discovered in WTCMS 1.0. It has stored XSS via the third text box (for the website statistics code). | |
| Modificada | Alta (8.8) | 0.61% | — | Wtcms Project Wtcms | 18/2/2019 | 17/6/2026 | An issue was discovered in WTCMS 1.0. It allows index.php?g=admin&m=setting&a=site_post CSRF. | |
| Modificada | Alta (7.5) | 1.8% | — | Wtcms Project Wtcms | 18/2/2019 | 17/6/2026 | An issue was discovered in WTCMS 1.0. It allows remote attackers to cause a denial of service (resource consumption) via crafted dimensions for the verification code image. |