Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

181 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)21%—Dedecms22/9/202417/6/2026
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaAlta (8.8)0.52%—Dedecms18/9/202417/6/2026
Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
ModificadaMedia (6.1)0.28%—Dedecms18/9/202417/6/2026
DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.
AnalizadaAlta (7.2)0.86%—Dedecms23/8/202417/6/2026
DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.
ModificadaMedia (5.1)0.67%—Dedecms21/7/202417/6/2026
A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated…
AnalizadaCrítica (9.8)0.73%—Dedecms28/5/202417/6/2026
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.
AnalizadaCrítica (9.8)0.47%—Dedecms23/5/202417/6/2026
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
AnalizadaMedia (5.5)0.28%—Dedecms17/5/202417/6/2026
DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.
AnalizadaMedia (5.3)1.1%—Dedecms14/5/202417/6/2026
A vulnerability classified as problematic has been found in DedeCMS 5.7.114. This affects an unknown part of the file /sys_verifies.php?action=view. The manipulation of the argument filename with the input ../../../../../etc/passwd leads to path traversal: '../filedir'. It is possible to initiate the attack remotely.…
AnalizadaMedia (6.5)0.82%—Dedecms14/5/202417/6/2026
An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.
AnalizadaMedia (4.3)0.42%—Dedecms7/5/202417/6/2026
A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. Affected is an unknown function of the file /src/dede/sys_safe.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaMedia (4.3)0.43%—Dedecms7/5/202417/6/2026
A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. This issue affects some unknown processing of the file /src/dede/sys_multiserv.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (4.3)0.43%—Dedecms7/5/202417/6/2026
A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/sys_group_edit.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263314 is…
AnalizadaMedia (4.3)0.43%—Dedecms7/5/202417/6/2026
A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/sys_group_add.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaMedia (4.3)0.42%—Dedecms7/5/202417/6/2026
A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/sys_info.php. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.…
AnalizadaMedia (4.3)0.42%—Dedecms7/5/202417/6/2026
A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (4.3)0.42%—Dedecms7/5/202417/6/2026
A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
AnalizadaMedia (4.3)0.42%—Dedecms7/5/202417/6/2026
A vulnerability was found in DedeCMS 5.7 and classified as problematic. This issue affects some unknown processing of the file /src/dede/tpl.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier…
AnalizadaMedia (4.3)0.42%—Dedecms7/5/202417/6/2026
A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/shops_delivery.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaMedia (4.3)0.43%—Dedecms7/5/202417/6/2026
A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/member_type.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaCrítica (9.1)0.65%—Dedecms6/5/202417/6/2026
DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
AnalizadaMedia (6.1)0.46%—Dedecms30/4/202417/6/2026
Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to execute arbitrary code via the typeid parameter in the makehtml_list_action.php component.
AnalizadaMedia (4.4)0.24%—Dedecms29/4/202417/6/2026
Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter.
AnalizadaMedia (5.3)0.23%—Dedecms25/4/202417/6/2026
Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payload to the stepselect_main.php component.
AnalizadaCrítica (9.8)0.67%—Dedecms22/4/202417/6/2026
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.