Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 1.1% | — | Aerocms Project Aerocms | 8/4/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field. | |
| Modificada | Alta (7.2) | 2.7% | — | Aerocms Project Aerocms | 8/4/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Alta (7.1) | 0.60% | — | Pyrocms | 8/10/2020 | 17/6/2026 | PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted. | |
| Modificada | Media (4.3) | 0.53% | — | Pyrocms | 8/10/2020 | 17/6/2026 | PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted. | |
| Modificada | Crítica (9.8) | 13% | — | Procmail | 16/11/2017 | 17/6/2026 | Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618. | |
| Modificada | Alta (7.5) | 2.4% | — | Aas9 Zerocms | 6/2/2015 | 17/6/2026 | SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a Modify Account action. NOTE: The article_id parameter to zero_view_article.php vector is… | |
| Modificada | Alta (7.5) | 8.5% | — | ProcmailCanonical Ubuntu Linux | 8/9/2014 | 17/6/2026 | Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes." | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Aas9 Zerocms | 29/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the Full Name field. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Aas9 Zerocms | 9/7/2014 | 17/6/2026 | SQL injection vulnerability in zero_transact_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a Submit Comment action. | |
| Modificada | Media (4.3) | 1.4% | — | Aas9 Zerocms | 3/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the article_id parameter. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Aas9 Zerocms | 11/6/2014 | 17/6/2026 | SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Apphp PHP Microcms | 22/9/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from… | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Apphp PHP Microcms | 22/9/2010 | 16/6/2026 | Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Amirocms Amiro.cms | 27/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the status_message parameter to (6) forum.php, (7) discussion.php, (8)… | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Amirocms Amiro.cms | 27/10/2009 | 16/6/2026 | Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message. | |
| Modificada | Media (6.8) | 1.3% | — | Exerocms Exero CMS | 24/6/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in Exero CMS 1.0.0 and 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to (1) custompage.php, (2) errors/404.php, (3) members/memberslist.php, (4) members/profile.php, (5) news/fullview.php, (6)… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Erocms | 20/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in eroCMS 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the site parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Mycrocms | 18/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in MycroCMS 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the entry_id parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Tyrocms | 5/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TyroCMS beta 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript URI in an img BBCode tag, or a JavaScript event in a (2) url BBCode tag or (3) color BBCode tag. | |
| Modificada | Alta (7.5) | 3.0% | — | John Hardin Procmail Email Sanitizer | 31/12/2002 | 16/6/2026 | The Email Sanitizer before 1.133 for Procmail allows remote attackers to bypass the mail filter and execute arbitrary code via crafted recursive multipart MIME attachments. | |
| Modificada | Media (6.2) | 0.32% | — | Procmail | 18/10/2001 | 16/6/2026 | Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain root privileges by sending a signal while a signal handling routine is already running. | |
| Modificada | Alta (7.5) | 2.5% | — | ProcmailCaldera Openlinux | 5/4/1999 | 16/6/2026 | Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file. | |
| Modificada | Baja (1.2) | 0.32% | — | Procmail | 5/4/1999 | 16/6/2026 | A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail. |