Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /admin/update_main_topic_img.php?topic_id=529. The manipulation of the argument stopic_id leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.1) | 0.37% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. This affects an unknown part of the file /admin/add_topic.php?category=BBS. The manipulation of the argument Cover Image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in itsourcecode Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search-notice.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.56% | — | Emiloi Content Management System | 6/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in itsourcecode Content Management System 1.0. Affected is an unknown function of the file /search_list.php. The manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (5.3) | 0.32% | — | Fannuo Enterprise Content Management SystemAI | 14/4/2025 | 17/6/2026 | A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/cms_chip.php. The manipulation of the argument del leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Modificada | Media (6) | 0.98% | — | Ddsn CM3 Acora Content Management System | 20/2/2025 | 5/7/2026 | DDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access sensitive information, such as system administrator credentials, by force browsing the endpoint and exploiting the 'file' parameter. By referencing specific files (e.g., cm3.xml),… | |
| Analizada | Alta (8.1) | 0.94% | — | Ddsn CM3 Acora Content Management System | 15/1/2025 | 17/6/2026 | DDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient input sanitization and validation in the "table" parameter. This flaw allows attackers to inject malicious SQL queries by directly incorporating user-supplied input into database… | |
| Analizada | Media (5.1) | 0.55% | — | Code-projects Content Management System | 9/1/2025 | 17/6/2026 | A vulnerability was found in code-projects Content Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/publishnews.php of the component Publish News Page. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack… | |
| Analizada | Media (6.9) | 1.4% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 4/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (5.9) | 0.28% | — | Netcat Content Management System | 19/9/2024 | 17/6/2026 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch. | |
| Analizada | Media (5.9) | 0.28% | — | Netcat Content Management System | 19/9/2024 | 17/6/2026 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/ https://netcat.ru/] . Versions 6.4.0.24248 and on have the patch. | |
| Analizada | Media (6.9) | 0.43% | — | Netcat Content Management System | 19/9/2024 | 17/6/2026 | A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v. 6.4.0.24126.2 and possibly others. Apply patch from vendor https://netcat.ru/… | |
| Aplazada | Alta (8.8) | 0.87% | — | JIN Fang Times Content Management SystemAI | 14/5/2024 | 17/6/2026 | Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter. | |
| Modificada | Alta (7.5) | 0.99% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component. | |
| Modificada | Media (6.1) | 0.61% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component. | |
| Modificada | Media (6.1) | 0.61% | — | Cusg Content Management System | 14/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component. | |
| Modificada | Media (6.1) | 0.46% | — | Content Management System Project Content Management System | 22/5/2023 | 17/6/2026 | IT Sourcecode Content Management System Project In PHP and MySQL With Source Code 1.0.0 is vulnerable to Cross Site Scripting (XSS) via /ecodesource/search_list.php. | |
| Modificada | Crítica (9.8) | 0.75% | — | Seltmann-webdesign Content Management System | 19/1/2023 | 17/6/2026 | Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php. | |
| Modificada | Alta (8.8) | 0.59% | — | Xjyunjing Yunjing Content Management System | 31/10/2022 | 17/6/2026 | A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /index/user/upload_img.html. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.4) | 0.50% | — | College Website Content Management System Project College Website Content Management System | 5/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields. | |
| Modificada | Media (4.8) | 0.54% | — | Totaljs Content Management System | 1/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page. | |
| Modificada | Media (5.4) | 0.57% | — | Macrob7 Macs Framework Content Management System Project Macrob7 Macs Framework Content Management System | 22/10/2021 | 17/6/2026 | Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field. | |
| Modificada | Media (6.1) | 0.84% | — | Content Management System Project Content Management System | 22/7/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter to content_management_system\admin\new_content.php | |
| Modificada | Media (4.8) | 0.63% | — | Generic Content Management System Project Generic Content Management System | 30/12/2018 | 17/6/2026 | Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/users.php user ID. | |
| Modificada | Media (4.8) | 0.64% | — | Generic Content Management System Project Generic Content Management System | 30/12/2018 | 17/6/2026 | Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/add_pictures.php article ID. |