Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.45% | — | Engineercms Project Engineercms | 12/5/2025 | 17/6/2026 | EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface. | |
| Analizada | Media (5.3) | 0.78% | — | Ctcms Project Ctcms | 11/5/2025 | 17/6/2026 | A vulnerability was found in CTCMS Content Management System 2.1.2. It has been classified as critical. Affected is the function del of the file ctcms\apps\controllers\admin\Tpl.php of the component File Handler. The manipulation of the argument File leads to path traversal. It is possible to launch the attack… | |
| Analizada | Crítica (9.8) | 0.78% | — | Qimou CMS Project Qimou CMS | 18/4/2025 | 17/6/2026 | An issue in Qimou CMS v.3.34.0 allows a remote attacker to execute arbitrary code via the upgrade.php component. | |
| Analizada | Media (4.3) | 0.41% | — | Bluecms Project Bluecms | 10/4/2025 | 17/6/2026 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request. | |
| Analizada | Media (4.8) | 0.34% | — | Pb-cms Project Pb-cms | 7/4/2025 | 17/6/2026 | A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin#links of the component Friendship Link Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (4.8) | 0.34% | — | Pb-cms Project Pb-cms | 7/4/2025 | 17/6/2026 | A vulnerability was found in LinZhaoguan pb-cms 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Classification Management Page. The manipulation of the argument Classification name leads to cross site scripting. The attack can be launched remotely.… | |
| Analizada | Baja (2.3) | 0.48% | — | Fastcms Project Fastcms | 3/4/2025 | 17/6/2026 | A vulnerability was found in FastCMS 0.1.5. It has been declared as critical. This vulnerability affects unknown code of the component JWT Handler. The manipulation leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears… | |
| Analizada | Media (5.1) | 0.50% | — | Pb-cms Project Pb-cms | 6/3/2025 | 17/6/2026 | A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserialization. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.48% | — | Shishuocms Project Shishuocms | 4/3/2025 | 17/6/2026 | A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function handleRequest of the file src/main/java/com/shishuo/cms/action/manage/ManageUpLoadAction.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely.… | |
| Analizada | Media (5.3) | 0.29% | — | Pb-cms Project Pb-cms | 27/2/2025 | 17/6/2026 | A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. This vulnerability affects unknown code of the component Logout. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.5) | 0.39% | — | Sucms Project Sucms | 27/2/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a crafted GET request. | |
| Analizada | Alta (7.5) | 0.67% | — | Sucms Project Sucms | 27/2/2025 | 17/6/2026 | An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request. | |
| Analizada | Media (5.3) | 0.29% | — | Ofcms Project Ofcms | 22/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.58% | — | Native-php-cms Project Native-php-cms | 15/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Fanli2012 native-php-cms 1.0. This issue affects some unknown processing of the file /fladmin/article_dodel.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.45% | — | Native-php-cms Project Native-php-cms | 15/1/2025 | 17/6/2026 | A vulnerability classified as critical was found in Fanli2012 native-php-cms 1.0. This vulnerability affects unknown code of the file /fladmin/friendlink_dodel.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.45% | — | Native-php-cms Project Native-php-cms | 15/1/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file product_list.php. The manipulation of the argument cat leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.33% | — | Native-php-cms Project Native-php-cms | 15/1/2025 | 17/6/2026 | A vulnerability has been found in Fanli2012 native-php-cms 1.0 and classified as problematic. This vulnerability affects unknown code of the file /fladmin/jump.php. The manipulation of the argument message/error leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.62% | — | Native-php-cms Project Native-php-cms | 15/1/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. This affects an unknown part of the file /fladmin/user_recoverpwd.php. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8.8) | 0.84% | — | Pb-cms Project Pb-cms | 9/1/2025 | 17/6/2026 | Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function. | |
| Analizada | Media (5.3) | 0.65% | — | Sucms Project Sucms | 9/1/2025 | 17/6/2026 | A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.1) | 0.29% | — | Pb-cms Project Pb-cms | 29/10/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of the component Theme Management Module. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.1) | 0.29% | — | Pb-cms Project Pb-cms | 29/10/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file /admin#article/edit?id=2 of the component Edit Article Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The… | |
| Analizada | Media (5.1) | 0.29% | — | Pb-cms Project Pb-cms | 29/10/2024 | 17/6/2026 | A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component Permission Management Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (4.8) | 0.25% | — | Wtcms Project Wtcms | 25/10/2024 | 17/6/2026 | An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS). | |
| Analizada | Media (4.7) | 0.29% | — | Wtcms Project Wtcms | 25/10/2024 | 17/6/2026 | WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter. |