Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.44%—Classcms Project Classcms20/7/202417/6/2026
A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:index&keyword=&kind=all. The manipulation of the argument order leads to cross site scripting. The attack can be launched remotely. The…
AnalizadaMedia (5.4)0.17%—Bosscms10/6/202417/6/2026
BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
AnalizadaAlta (7.1)0.37%—Bosscms25/4/202417/6/2026
Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.
ModificadaAlta (7.8)0.31%—Bosscms30/1/202417/6/2026
Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.
AnalizadaMedia (5.4)0.35%—Sscms3/10/202317/6/2026
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
ModificadaMedia (5.4)0.40%—Sscms Project Sscms3/10/202317/6/2026
SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.
ModificadaMedia (5.4)0.40%—Sscms Project Sscms3/10/202317/6/2026
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.
ModificadaMedia (4.8)0.46%—Impresscms13/7/202317/6/2026
A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php.
ModificadaMedia (6.1)0.56%—Sscms Siteserver CMS24/5/202317/6/2026
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to…
ModificadaMedia (4.9)0.83%—Sscms Siteserver CMS16/2/202317/6/2026
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
ModificadaCrítica (9.8)0.74%—Sscms Siteserver CMS27/1/202317/6/2026
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
ModificadaCrítica (9.8)0.97%—Sscms Siteserver CMS26/1/202317/6/2026
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
ModificadaCrítica (9.8)0.74%—Classcms Project Classcms22/12/202217/6/2026
here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5.
ModificadaMedia (6.5)0.29%—Bosscms28/11/202217/6/2026
Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.
ModificadaMedia (6.1)0.68%—Sscms Siteserver CMS2/6/202217/6/2026
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (5.4)0.70%—Sscms Siteserver CMS24/5/202217/6/2026
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
ModificadaAlta (8.8)1.2%—Sscms Siteserver CMS24/5/202217/6/2026
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
ModificadaCrítica (9.8)1.7%—Sscms Siteserver CMS24/5/202217/6/2026
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
ModificadaCrítica (9.8)1.5%—Bosscms5/5/202217/6/2026
An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.
ModificadaCrítica (9.8)2.8%—Sscms Siteserver CMS3/5/20229/7/2026
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
ModificadaAlta (7.2)4.1%—Impresscms5/4/202217/6/2026
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire…
ModificadaAlta (8.1)3.2%—Impresscms28/3/202217/6/2026
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
ModificadaCrítica (9.8)5.6%—Impresscms28/3/202217/6/2026
ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).
ModificadaCrítica (9.8)21%—Impresscms28/3/202217/6/2026
ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
ModificadaMedia (5.3)11%—Impresscms28/3/202217/6/2026
ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).