Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

192 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.40%—PSU Haxcms-nodejs21/7/202517/6/2026
HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of HAXcms uses an insecure default configuration designed for local development. The default configuration does not perform authorization or authentication checks. If a user…
AnalizadaMedia (5.6)0.30%—Qianfox Foxcms14/7/202517/6/2026
An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.
AnalizadaBaja (2.1)0.44%—Qianfox Foxcms14/7/202517/6/2026
A vulnerability was found in qianfox FoxCMS up to 1.2.5. It has been classified as critical. Affected is the function batchCope of the file app/admin/controller/Video.php. The manipulation of the argument ids leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.5)0.18%—PSU Haxcms-nodejsPSU Haxcms-php11/7/202517/6/2026
haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the application issues a refresh token when logging out. This vulnerability is fixed in 11.0.6.
AnalizadaBaja (2.1)0.45%—Qianfox Foxcms15/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file app/admin/controller/Download.php. The manipulation of the argument ids leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaAlta (8.8)1.5%—PSU Haxcms-nodejsPSU Haxcms-php9/6/202517/6/2026
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportSite` functionality obtains a URL string from a POST request and insufficiently validates user input. The `set_remote` function later passes this input into `proc_open`, yielding OS command injection.…
AnalizadaMedia (6.5)0.37%—PSU Haxcms-nodejsPSU Haxcms-php9/6/202517/6/2026
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, in the HAX site editor, users can create a website block to load another site in an iframe. The application allows users to supply a target URL in the website block. When the HAX site is visited, the client's…
AnalizadaMedia (6.5)0.51%—PSU Haxcms-php9/6/202517/6/2026
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbitrary files on the server by manipulating the location field written into…
AnalizadaMedia (6.1)0.27%—PSU Haxcms-nodejsPSU Haxcms-php9/6/202517/6/2026
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, the application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' endpoints take user input and store it in the JSON schema for…
AnalizadaAlta (8.4)0.22%—Foxcms3/6/202517/6/2026
Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.
AnalizadaMedia (5.3)0.49%—Foxcms25/5/202517/6/2026
A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the function batchCope of the file app/admin/controller/Article.php. The manipulation of the argument ids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to…
AnalizadaMedia (5.3)0.51%—Lmxcms11/5/202517/6/2026
A vulnerability classified as critical has been found in LmxCMS 1.41. Affected is the function manageZt of the file c\admin\ZtAction.class.php of the component POST Request Handler. The manipulation of the argument sortid leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.72%—Qianfox Foxcms5/5/202517/6/2026
An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
AnalizadaCrítica (9.1)0.67%—Qianfox Foxcms5/5/202517/6/2026
foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.
AnalizadaMedia (6.5)0.31%—Qianfox Foxcms5/5/202517/6/2026
foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.
AnalizadaAlta (7.2)0.39%—Foxcms17/4/202517/6/2026
FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.
AnalizadaAlta (7.2)0.39%—Foxcms17/4/202517/6/2026
In FOXCMS <=1.25, the installdb.php file has a time - based blind SQL injection vulnerability. The url_prefix, domain, and my_website POST parameters are directly concatenated into SQL statements without filtering.
AnalizadaCrítica (9.9)2.0%—PSU Haxcms-php8/4/202517/6/2026
HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX CMS PHP application call a ’save’ function in ’HAXCMSFile.php’. This save function uses a denylist to block specific file types from being uploaded to the server. This list is non-exhaustive and…
AnalizadaCrítica (9.8)47%💥 ExploitFoxcms27/3/202517/6/2026
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
AnalizadaMedia (5.3)0.32%—Qianfox Foxcms23/3/202517/6/2026
A vulnerability was found in FoxCMS 1.25 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.8)0.91%—Foxcms26/2/20255/7/2026
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.
ModificadaCrítica (9.8)1.3%—Foxcms26/2/20255/7/2026
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
AnalizadaMedia (5.1)0.17%—Ujcms Jspxcms21/2/202517/6/2026
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
AnalizadaBaja (2.1)0.54%—Lmxcms19/2/202517/6/2026
A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an unknown function of the file db.inc.php of the component Maintenance. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is…
AnalizadaMedia (6.9)0.63%—Qianfox Foxcms23/12/202417/6/2026
A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the component API Endpoint. The manipulation of the argument password leads to improper authorization. The attack can be launched remotely. The…
Orbitaley — Vulnerabilidades