Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.65% | — | Seacms | 18/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. The manipulation of the argument e_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.8) | 0.53% | — | Seacms | 3/4/2025 | 17/6/2026 | SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php. | |
| Modificada | Media (5.1) | 0.42% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php. | |
| Modificada | Media (5.1) | 0.42% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php. | |
| Modificada | Media (5.3) | 0.49% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php. | |
| Modificada | Media (6) | 0.24% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php. | |
| Modificada | Media (5.1) | 0.42% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php. | |
| Modificada | Media (5.1) | 0.42% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php. | |
| Modificada | Media (5.1) | 0.42% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php. | |
| Modificada | Media (5.1) | 0.42% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php. | |
| Modificada | Media (4.4) | 0.40% | — | Seacms | 26/2/2025 | 5/7/2026 | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Seacms | 25/2/2025 | 17/6/2026 | Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Seacms | 25/2/2025 | 17/6/2026 | Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Seacms | 25/2/2025 | 17/6/2026 | Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Seacms | 25/2/2025 | 17/6/2026 | Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Seacms | 25/2/2025 | 17/6/2026 | Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php. | |
| Analizada | Alta (8.8) | 0.51% | — | Seacms | 25/2/2025 | 17/6/2026 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database. | |
| Analizada | Media (6.5) | 0.30% | — | Seacms | 25/2/2025 | 17/6/2026 | Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php. | |
| Analizada | Crítica (9.8) | 0.82% | — | Seacms | 24/2/2025 | 17/6/2026 | SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component. | |
| Modificada | Crítica (9.8) | 0.52% | — | Seacms | 24/2/2025 | 17/6/2026 | Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php. | |
| Analizada | Crítica (9.1) | 0.90% | 💥 PoC | Seacms | 6/1/2025 | 17/6/2026 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk. | |
| Modificada | Crítica (9.1) | 0.93% | 💥 PoC | Seacms | 6/1/2025 | 5/7/2026 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely. | |
| Analizada | Crítica (9.8) | 1.1% | — | Seacms | 18/12/2024 | 17/6/2026 | SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext(). | |
| Modificada | Alta (8.8) | 0.60% | — | Seacms | 8/11/2024 | 5/7/2026 | SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php. | |
| Analizada | Crítica (9.8) | 1.00% | — | Seacms | 20/9/2024 | 17/6/2026 | SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method. |