Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

824 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.96%—Phome Empirecms3/5/202217/6/2026
EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php
ModificadaCrítica (9.8)1.1%—Bluecms Project Bluecms3/5/202217/6/2026
Bluecms 1.6 has a SQL injection vulnerability at cooike.
ModificadaMedia (6.5)1.1%—Kitesky Kitecms21/4/202217/6/2026
KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module.
ModificadaMedia (6.5)21%—Ritecms12/4/202217/6/2026
RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to…
ModificadaMedia (6.5)4.2%—Ritecms12/4/202217/6/2026
RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to…
ModificadaAlta (7.2)30%—Ritecms8/4/202217/6/2026
RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default.
ModificadaCrítica (9.8)22%—Ionizecms Ionize24/3/202217/6/2026
A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php.
ModificadaCrítica (9.8)2.2%—Dedecms14/2/202217/6/2026
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
ModificadaAlta (8.8)0.54%—Concretecms Concrete CMS9/2/202217/6/2026
A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users.
ModificadaCrítica (9.8)1.1%—Elitecms Elite CMS1/2/202217/6/2026
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php.
ModificadaCrítica (9.8)1.1%—Elitecms Elite CMS1/2/202217/6/2026
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php.
ModificadaCrítica (9.8)1.1%—Elitecms Elite CMS1/2/202217/6/2026
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php.
ModificadaCrítica (9.8)1.1%—Elitecms Elite CMS1/2/202217/6/2026
eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php.
ModificadaCrítica (9.1)17%—Elitecms Elite CMS1/2/202217/6/2026
An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files.
ModificadaCrítica (9.8)1.2%—Elitecms Elite CMS1/2/202217/6/2026
eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php.
ModificadaAlta (7.2)2.6%💥 PoCConcretecms Concrete CMS30/11/202117/6/2026
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
ModificadaAlta (7.5)1.5%—Concretecms Concrete CMS19/11/202117/6/2026
Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN. An attacker can pivot in the private LAN and exploit local network appsandb. SSRF Mitigation Bypass…
ModificadaMedia (5.3)0.86%—Concretecms Concrete CMS19/11/202117/6/2026
Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying…
ModificadaAlta (7.2)3.2%—Concretecms Concrete CMS19/11/202117/6/2026
A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they have disallowed file extensions. They are stored in a directory with…
ModificadaAlta (7.5)1.1%—Concretecms Concrete CMS19/11/202117/6/2026
In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS…
ModificadaAlta (8.8)0.98%—Concretecms Concrete CMS19/11/202117/6/2026
Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a check for group permissions before allowing…
ModificadaAlta (7.5)1.1%—Concretecms Concrete CMS19/11/202117/6/2026
Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered.For version 8.5.6, the following mitigations were put in place…
ModificadaCrítica (9.8)1.1%—Apostrophecms8/11/202117/6/2026
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older releases the user account in question can be…
ModificadaMedia (5.4)0.50%—Apostrophecms7/11/202117/6/2026
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed.
ModificadaMedia (6.1)0.83%—Dedecms22/10/202117/6/2026
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.