Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.44% | — | Classcms Project Classcms | 20/7/2024 | 17/6/2026 | A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:index&keyword=&kind=all. The manipulation of the argument order leads to cross site scripting. The attack can be launched remotely. The… | |
| Analizada | Media (5.4) | 0.17% | — | Bosscms | 10/6/2024 | 17/6/2026 | BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code." | |
| Analizada | Alta (7.1) | 0.37% | — | Bosscms | 25/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration. | |
| Modificada | Alta (7.8) | 0.31% | — | Bosscms | 30/1/2024 | 17/6/2026 | Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component. | |
| Analizada | Media (5.4) | 0.35% | — | Sscms | 3/10/2023 | 17/6/2026 | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component. | |
| Modificada | Media (5.4) | 0.40% | — | Sscms Project Sscms | 3/10/2023 | 17/6/2026 | SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component. | |
| Modificada | Media (5.4) | 0.40% | — | Sscms Project Sscms | 3/10/2023 | 17/6/2026 | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component. | |
| Modificada | Media (4.8) | 0.46% | — | Impresscms | 13/7/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php. | |
| Modificada | Media (6.1) | 0.56% | — | Sscms Siteserver CMS | 24/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (4.9) | 0.83% | — | Sscms Siteserver CMS | 16/2/2023 | 17/6/2026 | SiteServerCMS 7.1.3 sscms has a file read vulnerability. | |
| Modificada | Crítica (9.8) | 0.74% | — | Sscms Siteserver CMS | 27/1/2023 | 17/6/2026 | SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 0.97% | — | Sscms Siteserver CMS | 26/1/2023 | 17/6/2026 | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. | |
| Modificada | Crítica (9.8) | 0.74% | — | Classcms Project Classcms | 22/12/2022 | 17/6/2026 | here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. | |
| Modificada | Media (6.5) | 0.29% | — | Bosscms | 28/11/2022 | 17/6/2026 | Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module. | |
| Modificada | Media (6.1) | 0.68% | — | Sscms Siteserver CMS | 2/6/2022 | 17/6/2026 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (5.4) | 0.70% | — | Sscms Siteserver CMS | 24/5/2022 | 17/6/2026 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | |
| Modificada | Alta (8.8) | 1.2% | — | Sscms Siteserver CMS | 24/5/2022 | 17/6/2026 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | |
| Modificada | Crítica (9.8) | 1.7% | — | Sscms Siteserver CMS | 24/5/2022 | 17/6/2026 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.5% | — | Bosscms | 5/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server. | |
| Modificada | Crítica (9.8) | 2.8% | — | Sscms Siteserver CMS | 3/5/2022 | 9/7/2026 | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. | |
| Modificada | Alta (7.2) | 4.1% | — | Impresscms | 5/4/2022 | 17/6/2026 | SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire… | |
| Modificada | Alta (8.1) | 3.2% | — | Impresscms | 28/3/2022 | 17/6/2026 | ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal. | |
| Modificada | Crítica (9.8) | 5.6% | — | Impresscms | 28/3/2022 | 17/6/2026 | ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==). | |
| Modificada | Crítica (9.8) | 21% | — | Impresscms | 28/3/2022 | 17/6/2026 | ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection. | |
| Modificada | Media (5.3) | 11% | — | Impresscms | 28/3/2022 | 17/6/2026 | ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token). |