Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.37% | 💥 PoC | Motivian Content Management System | 4/6/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components. | |
| Analizada | Alta (8.2) | 0.59% | 💥 PoC | Motivian Content Management System | 4/6/2025 | 17/6/2026 | File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component. | |
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /admin/update_main_topic_img.php?topic_id=529. The manipulation of the argument stopic_id leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.1) | 0.37% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/add_topic.php?category=BBS. The manipulation of the argument Cover Image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search-notice.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unknown function of the file /search_list.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.9) | 0.34% | — | Opentext Content ManagementAI | 21/4/2025 | 17/6/2026 | User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes. | |
| Aplazada | Media (5.7) | 0.39% | — | Opentext Content ManagementAI | 21/4/2025 | 17/6/2026 | Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system. | |
| Aplazada | Media (5.3) | 0.32% | — | Fannuo Enterprise Content Management SystemAI | 14/4/2025 | 17/6/2026 | A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/cms_chip.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6) | 0.98% | 💥 PoC | Ddsn CM3 Acora Content Management System | 20/2/2025 | 5/7/2026 | DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files (e.g., cm3.xml),… | |
| Aplazada | Media (5.4) | 0.28% | — | Opentext Content ManagementAI | 4/2/2025 | 17/6/2026 | Improper Validation of Specified Type of Input vulnerability in OpenText™ Content Management (Extended ECM) allows Parameter Injection. A bad actor with the required OpenText Content Management privileges (not root) could expose the vulnerability to carry out a remote code execution attack on the target system. This… | |
| Analizada | Alta (8.1) | 0.94% | 💥 PoC | Ddsn CM3 Acora Content Management System | 15/1/2025 | 17/6/2026 | DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database… | |
| Analizada | Media (5.1) | 0.55% | — | Code-projects Content Management System | 9/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack… | |
| Analizada | Media (6.9) | 1.4% | 💥 Exploit | Anirbandutta9 News-buzzCode-projects Content Management System | 4/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (5.9) | 0.28% | — | Netcat Content Management System | 19/9/2024 | 17/6/2026 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch. | |
| Analizada | Media (5.9) | 0.28% | — | Netcat Content Management System | 19/9/2024 | 17/6/2026 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch. | |
| Analizada | Media (6.9) | 0.43% | — | Netcat Content Management System | 19/9/2024 | 17/6/2026 | A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/… | |
| Aplazada | Alta (8.8) | 0.87% | 💥 PoC | JIN Fang Times Content Management SystemAI | 14/5/2024 | 17/6/2026 | Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter. | |
| Modificada | Alta (7.5) | 0.99% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component. | |
| Modificada | Media (6.1) | 0.61% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component. | |
| Modificada | Media (6.1) | 0.61% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component. | |
| Modificada | Crítica (9.8) | 1.5% | — | Dokmee Enterprise Content Management | 14/12/2023 | 17/6/2026 | Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled. | |
| Modificada | Media (4.8) | 0.39% | — | Joedolson MY Content Management | 5/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joseph C Dolson My Content Management plugin <= 1.7.6 versions. | |
| Modificada | Media (6.1) | 0.46% | — | Content Management System Project Content Management System | 22/5/2023 | 17/6/2026 | IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php. | |
| Modificada | Crítica (9.8) | 0.75% | — | Seltmann-webdesign Content Management System | 19/1/2023 | 17/6/2026 | Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php. |