Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

595 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.60%—Pbootcms13/5/201817/6/2026
An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html.
ModificadaAlta (8.8)0.52%—Wtcms Project Wtcms22/4/201817/6/2026
WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.
ModificadaCrítica (9.8)1.4%—Pbootcms16/4/201817/6/2026
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php.
ModificadaAlta (8.8)0.51%—Pbootcms16/4/201817/6/2026
PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter.
ModificadaMedia (6.1)0.68%—Otcms24/3/201817/6/2026
OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.
ModificadaCrítica (9.8)2.2%—Exponentcms Exponent CMS7/3/201817/6/2026
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
ModificadaAlta (7.2)1.4%—Exponentcms Exponent CMS4/3/201817/6/2026
In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges.
ModificadaMedia (5.4)0.60%—Radiantcms Radiant CMS21/2/201817/6/2026
There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).
ModificadaAlta (7.2)1.3%—Dotcms19/2/201817/6/2026
SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.
ModificadaAlta (7.2)1.3%—Dotcms19/2/201817/6/2026
SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.
ModificadaCrítica (9.8)1.2%—Moxa Softcms LAB View18/1/201817/6/2026
A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified. Attackers can exploit this vulnerability to access SoftCMS without knowing the user's password.
ModificadaMedia (5.4)0.54%—Radiantcms Radiant CMS4/1/201817/6/2026
Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource.
ModificadaAlta (8.8)1.9%—Craftcms Craft CMS1/1/201817/6/2026
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension.
ModificadaMedia (5.3)1.8%—Boltcms Bolt10/11/201717/6/2026
Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.
ModificadaMedia (5.4)0.51%—Dotcms10/10/201717/6/2026
The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, and a templates Description field.
ModificadaMedia (6.1)1.5%—Exponentcms Exponent CMS28/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.
ModificadaCrítica (9.8)3.7%💥 ExploitSmartcms28/8/201717/6/2026
Multiple SQL injection vulnerabilities in SmartCMS v.2.
ModificadaMedia (6.1)0.99%—Smartwebsites Smartcms28/8/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2.
ModificadaAlta (7.2)7.7%—Dotcms20/7/201717/6/2026
Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to servlets/ajax_file_upload. This results in arbitrary code…
ModificadaMedia (5.4)0.55%—Boltcms Bolt17/7/201717/6/2026
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.
ModificadaMedia (5.4)0.55%—Boltcms Bolt17/7/201717/6/2026
Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header.
ModificadaMedia (5.4)2.8%💥 ExploitCraftcms Craft CMS8/6/201717/6/2026
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
ModificadaMedia (5.3)0.96%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
ModificadaMedia (6.1)0.84%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
ModificadaMedia (5.3)1.2%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
Orbitaley — Vulnerabilidades