Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.64% | — | Eyoucms | 14/11/2024 | 17/6/2026 | A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation of the argument activepath leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.5) | 0.53% | — | Eyoucms | 28/10/2024 | 17/6/2026 | An issue in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter. | |
| Analizada | Media (6.1) | 0.40% | — | Eyoucms | 28/10/2024 | 17/6/2026 | Cross Site Scripting vulnerability in eyouCMS v.1.6.7 allows a remote attacker to obtain sensitive information via a crafted script to the post parameter. | |
| Analizada | Alta (8.8) | 0.72% | — | Eyoucms | 7/4/2024 | 17/6/2026 | A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of the file /login.php?m=admin&c=Field&a=channel_edit of the component Backend. The manipulation of the argument channel_id leads to deserialization. The attack can be initiated remotely. The exploit… | |
| Analizada | Crítica (9.8) | 0.98% | — | Eyoucms | 14/3/2024 | 17/6/2026 | There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload. | |
| Modificada | Media (6.1) | 0.46% | — | Eyoucms | 1/2/2024 | 17/6/2026 | Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | |
| Modificada | Media (6.1) | 0.46% | — | Eyoucms | 1/2/2024 | 17/6/2026 | Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | |
| Modificada | Media (6.1) | 0.46% | — | Eyoucms | 1/2/2024 | 17/6/2026 | Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | |
| Modificada | Media (6.1) | 0.43% | — | Eyoucms | 1/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | |
| Modificada | Media (6.1) | 1.0% | — | Eyoucms | 1/2/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL. | |
| Modificada | Media (5.4) | 0.38% | — | Eyoucms | 14/12/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in EyouCMS-V1.6.5-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Registration Number parameter. | |
| Modificada | Media (4.8) | 0.39% | — | Eyoucms | 29/11/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Document Properties field at /login.php m=admin&c=Index&a=changeTableVal&_ajax=1&lang=cn. | |
| Modificada | Media (4.8) | 0.38% | — | Eyoucms | 29/11/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Field Title field at /login.php?m=admin&c=Field&a=arctype_add&_ajax=1&lang=cn. | |
| Modificada | Media (4.8) | 0.44% | — | Eyoucms | 29/11/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in EyouCMS v1.6.4-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu Name field at /login.php?m=admin&c=Index&a=changeTableVal&_ajax=1&lang=cn. | |
| Modificada | Media (5.4) | 0.41% | — | Eyoucms | 21/11/2023 | 17/6/2026 | eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users. | |
| Modificada | Media (6.1) | 1.2% | — | Eyoucms | 15/11/2023 | 17/6/2026 | EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t. | |
| Modificada | Media (5.4) | 0.35% | — | Gougucms | 27/10/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter. | |
| Modificada | Alta (7.5) | 0.45% | — | Gougucms | 27/10/2023 | 17/6/2026 | gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet. | |
| Modificada | Media (6.1) | 0.48% | — | Ucms Project Ucms | 17/9/2023 | 17/6/2026 | A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file ajax.php?do=strarraylist. The manipulation of the argument strdefault leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.3) | 25% | — | Eyoucms | 20/7/2023 | 17/6/2026 | eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. | |
| Modificada | Media (5.4) | 0.38% | — | Eyoucms | 6/7/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Basic Website Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Media (5.4) | 0.34% | — | Eyoucms | 6/7/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Image Upload module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Media (5.4) | 0.38% | — | Eyoucms | 6/7/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Basic Information module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Media (5.4) | 0.34% | — | Eyoucms | 6/7/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Column management module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Media (5.4) | 0.34% | — | Eyoucms | 6/7/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the custom variables module of eyoucms v1.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. |