Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

61 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.79%—Company Website CMS Project Company Website CMS2/11/202317/6/2026
A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit…
ModificadaMedia (6.1)0.48%—Maxsite CMS3/7/202317/6/2026
Cross Site Scripting vulnerability in Maxsite CMS v.108.7 allows a remote attacker to execute arbitrary code via the f_content parameter in the admin/page_new file.
ModificadaAlta (8.8)1.0%—Kensite CMS Project Kensite CMS26/8/202217/6/2026
Kensite CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities via the name and oldname parameters at /framework/mod/db/DBMapper.xml.
ModificadaMedia (5.4)0.60%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue affects some unknown processing of the file /dashboard/contact. The manipulation of the argument phone leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)1.2%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /dashboard/settings. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file /dashboard/add-portfolio.php. The manipulation of the argument ufile leads to unrestricted upload. The attack may be launched remotely. The identifier of this…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Company Website CMS. Affected is an unknown function of the file /dashboard/add-service.php of the component Add Service Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. VDB-206022 is the…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been declared as critical. This vulnerability affects unknown code of the file /dashboard/add-blog.php of the component Add Blog. The manipulation of the argument ufile leads to unrestricted upload. The attack can be initiated remotely. VDB-205882…
ModificadaCrítica (9.8)0.70%—Company Website CMS Project Company Website CMS11/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been classified as critical. This affects an unknown part of the file /dashboard/updatelogo.php of the component Background Upload Logo Icon. The manipulation of the argument xfile/ufile leads to unrestricted upload. It is possible to initiate the…
ModificadaMedia (6.1)0.46%—Company Website CMS Project Company Website CMS9/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add-blog.php. The manipulation leads to cross site scripting. The attack may be launched remotely. VDB-205838 is the identifier assigned to this…
ModificadaMedia (6.5)0.63%—Company Website/cms Project Company Website/cms8/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been…
ModificadaAlta (8.8)0.85%—Company Website CMS Project Company Website CMS6/8/202217/6/2026
A vulnerability was found in SourceCodester Company Website CMS and classified as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205817 was…
ModificadaMedia (5.4)0.49%—Max-3000 Maxsite CMS28/2/202217/6/2026
Maxsite CMS v108 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_tags at /admin/page_edit/3.
ModificadaAlta (8.1)1.1%—Max-3000 Maxsite CMS28/2/202217/6/2026
Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.
ModificadaCrítica (9.8)3.0%—Max-3000 Maxsite CMS28/2/202217/6/2026
A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (5.4)0.49%—Max-3000 Maxsite CMS28/2/202217/6/2026
Maxsite CMS v180 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the parameter f_file_description at /admin/files.
ModificadaCrítica (9.8)3.6%—Max-3000 Maxsite CMS10/12/202117/6/2026
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
ModificadaMedia (6.1)3.4%—Maxsite CMS3/8/202117/6/2026
A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attackers to inject arbitrary web script to a page.
ModificadaMedia (4.3)1.7%—Cutesite CMS2/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6)0.95%—Cutesite CMS2/11/201116/6/2026
SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.97%—4site CMS3/11/201016/6/2026
SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the i and th vectors are already covered by CVE-2009-0646.
ModificadaMedia (6)1.5%—Karl Core Bandsite CMS22/4/201016/6/2026
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request…
ModificadaAlta (7.5)0.99%—Karl Core Bandsite CMS22/4/201016/6/2026
SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php.
ModificadaMedia (6.8)0.94%—Grayscalecms Bandsite CMS24/8/200916/6/2026
Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of administrators and force a logout via adminpanel/logout.php.
ModificadaMedia (4.3)1.5%—Grayscalecms Bandsite CMS24/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbitrary HTML or web script via the type parameter.