Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.20%—Yzmcms23/9/20255/7/2026
Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.
ModificadaCrítica (9.8)0.88%—Sueamcms Project Sueamcms12/9/20255/7/2026
File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.
AplazadaBaja (2.1)0.35%—Uxblondon BoomcmsAI3/9/202517/6/2026
Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to spy on users via JavaScript. This type of attack is based on social engineering and depends entirely on the browser chosen by the user, so it is perceived as a minor threat…
AnalizadaMedia (6.1)0.21%—Formcms28/8/202525/9/2026
FormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload .html files containing malicious JavaScript, which are accessible via a public URL. When a privileged user accesses the file, the script executes in their browser context.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
ModificadaMedia (5.4)0.24%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.
ModificadaCrítica (9.8)0.78%—Mingsoft Mcms21/4/20255/7/2026
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
AnalizadaMedia (5.3)0.54%—Yzmcms8/4/202517/6/2026
A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor…
AnalizadaCrítica (9.8)0.50%—Sem-cms Semcms27/3/202517/6/2026
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
AnalizadaMedia (5.3)0.51%—Sem-cms Semcms8/1/202517/6/2026
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaBaja (3.8)0.29%—Sem-cms Semcms3/12/202417/6/2026
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
ModificadaMedia (4.9)0.55%—Sem-cms Semcms20/11/20245/7/2026
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
AnalizadaCrítica (9.8)0.51%—Sem-cms Semcms20/9/202417/6/2026
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
AnalizadaAlta (8.1)0.81%—Mingsoft Mcms3/9/202417/6/2026
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
AplazadaAlta (7.5)0.41%—WmcmsAI19/7/202417/6/2026
An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.
AnalizadaMedia (6.1)0.29%—Yzmcms5/7/202417/6/2026
A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.
AnalizadaMedia (5.9)0.39%—Sem-cms Semcms4/6/202417/6/2026
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.
AnalizadaAlta (7.5)0.70%—Sem-cms Semcms4/6/202417/6/2026
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.