Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.60% | — | Pbootcms | 13/5/2018 | 17/6/2026 | An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html. | |
| Modificada | Alta (8.8) | 0.52% | — | Wtcms Project Wtcms | 22/4/2018 | 17/6/2026 | WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI. | |
| Modificada | Crítica (9.8) | 1.4% | — | Pbootcms | 16/4/2018 | 17/6/2026 | PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php. | |
| Modificada | Alta (8.8) | 0.51% | — | Pbootcms | 16/4/2018 | 17/6/2026 | PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter. | |
| Modificada | Media (6.1) | 0.68% | — | Otcms | 24/3/2018 | 17/6/2026 | OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request. | |
| Modificada | Crítica (9.8) | 2.2% | — | Exponentcms Exponent CMS | 7/3/2018 | 17/6/2026 | Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location." | |
| Modificada | Alta (7.2) | 1.4% | — | Exponentcms Exponent CMS | 4/3/2018 | 17/6/2026 | In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges. | |
| Modificada | Media (5.4) | 0.60% | — | Radiantcms Radiant CMS | 21/2/2018 | 17/6/2026 | There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields). | |
| Modificada | Alta (7.2) | 1.3% | — | Dotcms | 19/2/2018 | 17/6/2026 | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter. | |
| Modificada | Alta (7.2) | 1.3% | — | Dotcms | 19/2/2018 | 17/6/2026 | SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Moxa Softcms LAB View | 18/1/2018 | 17/6/2026 | A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified. Attackers can exploit this vulnerability to access SoftCMS without knowing the user's password. | |
| Modificada | Media (5.4) | 0.54% | — | Radiantcms Radiant CMS | 4/1/2018 | 17/6/2026 | Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource. | |
| Modificada | Alta (8.8) | 1.9% | — | Craftcms Craft CMS | 1/1/2018 | 17/6/2026 | Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension. | |
| Modificada | Media (5.3) | 1.8% | — | Boltcms Bolt | 10/11/2017 | 17/6/2026 | Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php. | |
| Modificada | Media (5.4) | 0.51% | — | Dotcms | 10/10/2017 | 17/6/2026 | The dotCMS 4.1.1 application is vulnerable to Stored Cross-Site Scripting (XSS) affecting a vanity-urls Title field, a containers Description field, and a templates Description field. | |
| Modificada | Media (6.1) | 1.5% | — | Exponentcms Exponent CMS | 28/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2. | |
| Modificada | Crítica (9.8) | 3.7% | 💥 Exploit | Smartcms | 28/8/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in SmartCMS v.2. | |
| Modificada | Media (6.1) | 0.99% | — | Smartwebsites Smartcms | 28/8/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2. | |
| Modificada | Alta (7.2) | 7.7% | — | Dotcms | 20/7/2017 | 17/6/2026 | Arbitrary file upload vulnerability in com/dotmarketing/servlets/AjaxFileUploadServlet.class in dotCMS 4.1.1 allows remote authenticated administrators to upload .jsp files to arbitrary locations via directory traversal sequences in the fieldName parameter to servlets/ajax_file_upload. This results in arbitrary code… | |
| Modificada | Media (5.4) | 0.55% | — | Boltcms Bolt | 17/7/2017 | 17/6/2026 | Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry. | |
| Modificada | Media (5.4) | 0.55% | — | Boltcms Bolt | 17/7/2017 | 17/6/2026 | Bolt CMS 3.2.14 allows stored XSS by uploading an SVG document with a "Content-Type: image/svg+xml" header. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | Craftcms Craft CMS | 8/6/2017 | 17/6/2026 | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. | |
| Modificada | Media (5.3) | 0.96% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message. | |
| Modificada | Media (6.1) | 0.84% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052. | |
| Modificada | Media (5.3) | 1.2% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. |