Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)1.1%—Aerocms Project Aerocms8/4/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.
ModificadaAlta (7.2)2.7%—Aerocms Project Aerocms8/4/202217/6/2026
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (7.1)0.60%—Pyrocms8/10/202017/6/2026
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted.
ModificadaMedia (4.3)0.53%—Pyrocms8/10/202017/6/2026
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/pages/delete/ URI: pages will be deleted.
ModificadaCrítica (9.8)13%—Procmail16/11/201717/6/2026
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
ModificadaAlta (7.5)2.4%—Aas9 Zerocms6/2/201517/6/2026
SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a Modify Account action. NOTE: The article_id parameter to zero_view_article.php vector is…
ModificadaAlta (7.5)8.5%—ProcmailCanonical Ubuntu Linux8/9/201417/6/2026
Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."
ModificadaMedia (4.3)3.2%💥 ExploitAas9 Zerocms29/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the Full Name field.
ModificadaAlta (7.5)1.2%💥 ExploitAas9 Zerocms9/7/201417/6/2026
SQL injection vulnerability in zero_transact_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter in a Submit Comment action.
ModificadaMedia (4.3)1.4%—Aas9 Zerocms3/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the article_id parameter.
ModificadaAlta (7.5)6.3%💥 ExploitAas9 Zerocms11/6/201417/6/2026
SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
ModificadaMedia (6.8)1.1%💥 ExploitApphp PHP Microcms22/9/201016/6/2026
Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from…
ModificadaMedia (6.8)2.4%💥 ExploitApphp PHP Microcms22/9/201016/6/2026
Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
ModificadaMedia (4.3)1.8%💥 ExploitAmirocms Amiro.cms27/10/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the status_message parameter to (6) forum.php, (7) discussion.php, (8)…
ModificadaMedia (5)2.6%💥 ExploitAmirocms Amiro.cms27/10/200916/6/2026
Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.
ModificadaMedia (6.8)1.3%—Exerocms Exero CMS24/6/200816/6/2026
Multiple directory traversal vulnerabilities in Exero CMS 1.0.0 and 1.0.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter to (1) custompage.php, (2) errors/404.php, (3) members/memberslist.php, (4) members/profile.php, (5) news/fullview.php, (6)…
ModificadaAlta (7.5)0.97%💥 ExploitErocms20/6/200816/6/2026
SQL injection vulnerability in index.php in eroCMS 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the site parameter.
ModificadaAlta (7.5)0.97%💥 ExploitMycrocms18/6/200816/6/2026
SQL injection vulnerability in index.php in MycroCMS 0.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the entry_id parameter.
ModificadaMedia (6.8)1.3%—Tyrocms5/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in TyroCMS beta 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript URI in an img BBCode tag, or a JavaScript event in a (2) url BBCode tag or (3) color BBCode tag.
ModificadaAlta (7.5)3.0%—John Hardin Procmail Email Sanitizer31/12/200216/6/2026
The Email Sanitizer before 1.133 for Procmail allows remote attackers to bypass the mail filter and execute arbitrary code via crafted recursive multipart MIME attachments.
ModificadaMedia (6.2)0.32%—Procmail18/10/200116/6/2026
Race condition in signal handling of procmail 3.20 and earlier, when running setuid, allows local users to cause a denial of service or gain root privileges by sending a signal while a signal handling routine is already running.
ModificadaAlta (7.5)2.5%—ProcmailCaldera Openlinux5/4/199916/6/2026
Buffer overflow in procmail before version 3.12 allows remote or local attackers to execute commands via expansions in the procmailrc configuration file.
ModificadaBaja (1.2)0.32%—Procmail5/4/199916/6/2026
A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.
Orbitaley — Vulnerabilidades