Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

137 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.37%💥 PoCMotivian Content Management System4/6/202517/6/2026
Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components.
AnalizadaAlta (8.2)0.59%💥 PoCMotivian Content Management System4/6/202517/6/2026
File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component.
AnalizadaMedia (6.9)0.56%—Emiloi Content Management System6/5/202517/6/2026
A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /admin/update_main_topic_img.php?topic_id=529. The manipulation of the argument stopic_id leads to sql injection. The attack can be initiated remotely. The exploit has…
AnalizadaMedia (5.1)0.37%—Emiloi Content Management System6/5/202517/6/2026
A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/add_topic.php?category=BBS. The manipulation of the argument Cover Image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (6.9)0.56%—Emiloi Content Management System6/5/202517/6/2026
A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search-notice.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaMedia (6.9)0.56%—Emiloi Content Management System6/5/202517/6/2026
A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unknown function of the file /search_list.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AplazadaMedia (5.9)0.34%—Opentext Content ManagementAI21/4/202517/6/2026
User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.
AplazadaMedia (5.7)0.39%—Opentext Content ManagementAI21/4/202517/6/2026
Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system.
AplazadaMedia (5.3)0.32%—Fannuo Enterprise Content Management SystemAI14/4/202517/6/2026
A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/cms_chip.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been…
ModificadaMedia (6)0.98%💥 PoCDdsn CM3 Acora Content Management System20/2/20255/7/2026
DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files (e.g., cm3.xml),…
AplazadaMedia (5.4)0.28%—Opentext Content ManagementAI4/2/202517/6/2026
Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system. This…
AnalizadaAlta (8.1)0.94%💥 PoCDdsn CM3 Acora Content Management System15/1/202517/6/2026
DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database…
AnalizadaMedia (5.1)0.55%—Code-projects Content Management System9/1/202517/6/2026
A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack…
AnalizadaMedia (6.9)1.4%💥 ExploitAnirbandutta9 News-buzzCode-projects Content Management System4/11/202417/6/2026
A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit…
AnalizadaMedia (5.9)0.28%—Netcat Content Management System19/9/202417/6/2026
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.
AnalizadaMedia (5.9)0.28%—Netcat Content Management System19/9/202417/6/2026
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch.
AnalizadaMedia (6.9)0.43%—Netcat Content Management System19/9/202417/6/2026
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/…
AplazadaAlta (8.8)0.87%💥 PoCJIN Fang Times Content Management SystemAI14/5/202417/6/2026
Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.
ModificadaAlta (7.5)0.99%—Cusg Content Management System14/2/202417/6/2026
Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.
ModificadaMedia (6.1)0.61%—Cusg Content Management System14/2/202417/6/2026
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component.
ModificadaMedia (6.1)0.61%—Cusg Content Management System14/2/202417/6/2026
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.
ModificadaCrítica (9.8)1.5%—Dokmee Enterprise Content Management14/12/202317/6/2026
Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.
ModificadaMedia (4.8)0.39%—Joedolson MY Content Management5/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joseph C Dolson My Content Management plugin <= 1.7.6 versions.
ModificadaMedia (6.1)0.46%—Content Management System Project Content Management System22/5/202317/6/2026
IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php.
ModificadaCrítica (9.8)0.75%—Seltmann-webdesign Content Management System19/1/202317/6/2026
Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.
Orbitaley — Vulnerabilidades