Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

125 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.65%—Seacms18/4/202517/6/2026
A vulnerability, which was classified as critical, has been found in SeaCMS up to 13.3. This issue affects some unknown processing of the file /admin_link.php?action=delall. The manipulation of the argument e_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
AnalizadaCrítica (9.8)0.53%—Seacms3/4/202517/6/2026
SeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
ModificadaMedia (5.1)0.42%—Seacms26/2/20255/7/2026
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.
ModificadaMedia (5.1)0.42%—Seacms26/2/20255/7/2026
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.
ModificadaMedia (5.3)0.49%—Seacms26/2/20255/7/2026
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.
ModificadaMedia (6)0.24%—Seacms26/2/20255/7/2026
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.
ModificadaMedia (5.1)0.42%—Seacms26/2/20255/7/2026
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.
ModificadaMedia (5.1)0.42%—Seacms26/2/20255/7/2026
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.
ModificadaMedia (5.1)0.42%—Seacms26/2/20255/7/2026
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
ModificadaMedia (5.1)0.42%—Seacms26/2/20255/7/2026
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.
ModificadaMedia (4.4)0.40%—Seacms26/2/20255/7/2026
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.
AnalizadaCrítica (9.8)0.52%—Seacms25/2/202517/6/2026
Seacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.
AnalizadaCrítica (9.8)0.52%—Seacms25/2/202517/6/2026
Seacms <13.3 is vulnerable to SQL Injection in admin_pay.php.
AnalizadaCrítica (9.8)0.52%—Seacms25/2/202517/6/2026
Seacms <=13.3 is vulnerable to SQL Injection in admin_zyk.php.
AnalizadaCrítica (9.8)0.52%—Seacms25/2/202517/6/2026
Seacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.
AnalizadaCrítica (9.8)0.52%—Seacms25/2/202517/6/2026
Seacms <=13.3 is vulnerable to SQL Injection in admin_paylog.php.
AnalizadaAlta (8.8)0.51%—Seacms25/2/202517/6/2026
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
AnalizadaMedia (6.5)0.30%—Seacms25/2/202517/6/2026
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect_news.php.
AnalizadaCrítica (9.8)0.82%—Seacms24/2/202517/6/2026
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
ModificadaCrítica (9.8)0.52%—Seacms24/2/202517/6/2026
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
AnalizadaCrítica (9.1)0.90%💥 PoCSeacms6/1/202517/6/2026
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.
ModificadaCrítica (9.1)0.93%💥 PoCSeacms6/1/20255/7/2026
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.
AnalizadaCrítica (9.8)1.1%—Seacms18/12/202417/6/2026
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
ModificadaAlta (8.8)0.60%—Seacms8/11/20245/7/2026
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.
AnalizadaCrítica (9.8)1.00%—Seacms20/9/202417/6/2026
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
Orbitaley — Vulnerabilidades