Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.53%—Wbce CMS21/11/202217/6/2026
A cross-site scripting (XSS) vulnerability in the Show Advanced Option module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Section Header field.
ModificadaMedia (4.8)0.53%—Wbce CMS21/11/202217/6/2026
A cross-site scripting (XSS) vulnerability in the Modify Page module of WBCE CMS v1.5.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Source field.
ModificadaAlta (7.5)0.84%—Wbce CMS15/11/202217/6/2026
A vulnerability, which was classified as problematic, has been found in WBCE CMS. Affected by this issue is the function increase_attempts of the file wbce/framework/class.login.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper restriction of excessive…
ModificadaMedia (5.4)0.86%—Wbce CMS17/5/202217/6/2026
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.
ModificadaMedia (5.4)1.6%💥 ExploitWbce CMS17/5/202217/6/2026
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.
ModificadaMedia (6.1)0.98%—Wbce CMS28/4/202217/6/2026
WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS).
ModificadaAlta (7.8)1.2%—Wbce CMS24/2/202217/6/2026
A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (7.8)1.2%—Wbce CMS24/2/202217/6/2026
A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaCrítica (9.8)38%💥 ExploitWbce CMS9/12/202117/6/2026
wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
ModificadaAlta (7.2)1.4%—Wbce CMS14/10/201917/6/2026
A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: place PHP code in a .jpg file, and then change the file's base name to filename.ph and change the…
ModificadaMedia (4.8)0.63%—Wbce CMS25/1/201817/6/2026
Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118.
ModificadaMedia (4.8)0.61%—Wbce CMS17/11/201717/6/2026
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search
ModificadaAlta (7.2)1.3%—Wbce CMS28/4/201717/6/2026
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (8.6)3.5%—Wbce CMS28/4/201717/6/2026
Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (6.1)1.2%—Wbce CMS28/4/201717/6/2026
Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Orbitaley — Vulnerabilidades