Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.96% | — | Phome Empirecms | 3/5/2022 | 17/6/2026 | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php | |
| Modificada | Crítica (9.8) | 1.1% | — | Bluecms Project Bluecms | 3/5/2022 | 17/6/2026 | Bluecms 1.6 has a SQL injection vulnerability at cooike. | |
| Modificada | Media (6.5) | 1.1% | — | Kitesky Kitecms | 21/4/2022 | 17/6/2026 | KiteCMS v1.1.1 was discovered to contain an arbitrary file read vulnerability via the background management module. | |
| Modificada | Media (6.5) | 21% | — | Ritecms | 12/4/2022 | 17/6/2026 | RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to delete any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to… | |
| Modificada | Media (6.5) | 4.2% | — | Ritecms | 12/4/2022 | 17/6/2026 | RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel. Exploiting the vulnerability allows an authenticated attacker to overwrite any file in the web root (along with any other file on the server that the PHP process user has the proper permissions to… | |
| Modificada | Alta (7.2) | 30% | — | Ritecms | 8/4/2022 | 17/6/2026 | RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default. | |
| Modificada | Crítica (9.8) | 22% | — | Ionizecms Ionize | 24/3/2022 | 17/6/2026 | A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php. | |
| Modificada | Crítica (9.8) | 2.2% | — | Dedecms | 14/2/2022 | 17/6/2026 | DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter. | |
| Modificada | Alta (8.8) | 0.54% | — | Concretecms Concrete CMS | 9/2/2022 | 17/6/2026 | A cross-site request forgery vulnerability exists in Concrete CMS <v9 that could allow an attacker to make requests on behalf of other users. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_user.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/functions/functions.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_post.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 was discovered to contain a SQL injection vulnerability via /admin/edit_page.php. | |
| Modificada | Crítica (9.1) | 17% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | An issue in /admin/delete_image.php of eliteCMS v1.0 allows attackers to delete arbitrary files. | |
| Modificada | Crítica (9.8) | 1.2% | — | Elitecms Elite CMS | 1/2/2022 | 17/6/2026 | eliteCMS v1.0 is vulnerable to Insecure Permissions via manage_uploads.php. | |
| Modificada | Alta (7.2) | 2.6% | 💥 PoC | Concretecms Concrete CMS | 30/11/2021 | 17/6/2026 | An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password. | |
| Modificada | Alta (7.5) | 1.5% | — | Concretecms Concrete CMS | 19/11/2021 | 17/6/2026 | Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN. An attacker can pivot in the private LAN and exploit local network appsandb. SSRF Mitigation Bypass… | |
| Modificada | Media (5.3) | 0.86% | — | Concretecms Concrete CMS | 19/11/2021 | 17/6/2026 | Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying… | |
| Modificada | Alta (7.2) | 3.2% | — | Concretecms Concrete CMS | 19/11/2021 | 17/6/2026 | A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they have disallowed file extensions. They are stored in a directory with… | |
| Modificada | Alta (7.5) | 1.1% | — | Concretecms Concrete CMS | 19/11/2021 | 17/6/2026 | In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS… | |
| Modificada | Alta (8.8) | 0.98% | — | Concretecms Concrete CMS | 19/11/2021 | 17/6/2026 | Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a check for group permissions before allowing… | |
| Modificada | Alta (7.5) | 1.1% | — | Concretecms Concrete CMS | 19/11/2021 | 17/6/2026 | Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered.For version 8.5.6, the following mitigations were put in place… | |
| Modificada | Crítica (9.8) | 1.1% | — | Apostrophecms | 8/11/2021 | 17/6/2026 | Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third party could not be locked out by those means. As a mitigation for older releases the user account in question can be… | |
| Modificada | Media (5.4) | 0.50% | — | Apostrophecms | 7/11/2021 | 17/6/2026 | Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once viewed. | |
| Modificada | Media (6.1) | 0.83% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters. |