Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
59 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.91% | — | Foxcms | 26/2/2025 | 5/7/2026 | An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file. | |
| Modificada | Crítica (9.8) | 1.3% | — | Foxcms | 26/2/2025 | 5/7/2026 | FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php. | |
| Analizada | Media (6.9) | 0.63% | — | Qianfox Foxcms | 23/12/2024 | 17/6/2026 | A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API Endpoint. The manipulation of the argument password leads to improper authorization. The attack can be launched remotely. The… | |
| Analizada | Media (5.3) | 0.75% | — | Qianfox Foxcms | 23/12/2024 | 17/6/2026 | A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File Handler. The manipulation of the argument database password leads to code injection. It is possible to launch the attack remotely. The… | |
| Modificada | Crítica (9.8) | 1.2% | — | Bloofoxcms | 11/8/2023 | 17/6/2026 | File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module. | |
| Modificada | Crítica (9.8) | 4.2% | — | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit. | |
| Modificada | Crítica (9.8) | 4.2% | — | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit. | |
| Modificada | Crítica (9.8) | 3.4% | — | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit. | |
| Modificada | Crítica (9.8) | 4.2% | — | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit. | |
| Modificada | Crítica (9.8) | 4.4% | — | Bloofoxcms | 14/6/2023 | 9/7/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit. | |
| Modificada | Crítica (9.8) | 4.2% | — | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit. | |
| Modificada | Crítica (9.8) | 1.0% | — | Bloofoxcms | 14/6/2023 | 17/6/2026 | bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit. | |
| Modificada | Alta (8.8) | 0.72% | — | Bloofoxcms | 13/4/2023 | 17/6/2026 | bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1. | |
| Modificada | Crítica (9.1) | 1.2% | — | Bloofoxcms | 13/4/2023 | 9/7/2026 | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. | |
| Modificada | Media (6.5) | 1.0% | — | Bloofoxcms | 26/1/2023 | 17/6/2026 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php. | |
| Modificada | Alta (8.8) | 1.3% | — | Bloofoxcms | 26/4/2022 | 17/6/2026 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | |
| Modificada | Crítica (9.8) | 1.4% | — | Bloofoxcms | 24/2/2022 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php. | |
| Modificada | Media (5.4) | 0.49% | — | Bloofoxcms | 24/2/2022 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php. | |
| Modificada | Baja (2.7) | 0.97% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files. | |
| Modificada | Media (5.4) | 0.83% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. | |
| Modificada | Crítica (9.8) | 1.9% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files). | |
| Modificada | Media (6.5) | 0.84% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). | |
| Modificada | Media (6.5) | 1.4% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. | |
| Modificada | Alta (8.8) | 1.3% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header. | |
| Modificada | Media (6.5) | 0.57% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely). |