Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.3%—Wtcms Project Wtcms18/2/201917/6/2026
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type: image/gif" header.
ModificadaMedia (6.5)1.5%—Hongcms Project Hongcms17/2/201917/6/2026
HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI.
ModificadaMedia (6.1)0.83%—Frog CMS Project Frog CMS11/2/201917/6/2026
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element.
ModificadaMedia (5.4)0.64%—Frog CMS Project Frog CMS11/2/201917/6/2026
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field.
ModificadaAlta (7.5)1.5%—Frog CMS Project Frog CMS11/2/201917/6/2026
Frog CMS 0.9.5 provides a directory listing for a /public request.
ModificadaAlta (7.2)2.1%—Frog CMS Project Frog CMS11/2/201917/6/2026
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
ModificadaMedia (5.4)0.64%—Frog CMS Project Frog CMS11/2/201917/6/2026
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field.
ModificadaAlta (7.2)2.1%—Frog CMS Project Frog CMS11/2/201917/6/2026
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.
ModificadaAlta (7.2)2.1%—Frog CMS Project Frog CMS11/2/201917/6/2026
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.
ModificadaCrítica (9.8)1.5%—Baijiacms Project Baijiacms7/2/201917/6/2026
An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request.
ModificadaMedia (6.1)0.68%—Frog CMS Project Frog CMS12/1/201917/6/2026
Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI).
ModificadaMedia (4.8)0.58%—Frog CMS Project Frog CMS9/1/201917/6/2026
Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field.
ModificadaMedia (4.8)0.56%—No-cms Project No-cms31/12/201817/6/2026
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article "keyword" parameter.
ModificadaMedia (4.8)0.56%—No-cms Project No-cms31/12/201817/6/2026
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter.
ModificadaMedia (4.8)0.56%—Frogcms Project Frogcms31/12/201817/6/2026
FROG CMS 0.9.5 has XSS via the admin/?/snippet/add name parameter, which is mishandled during an edit action, a related issue to CVE-2018-10319.
ModificadaMedia (4.8)0.56%—Ucms Project Ucms30/12/201817/6/2026
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
ModificadaMedia (6.1)0.71%—Ucms Project Ucms30/12/201817/6/2026
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
ModificadaAlta (8.8)1.5%—Ucms Project Ucms30/12/201817/6/2026
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
ModificadaAlta (8.8)0.53%—Ucms Project Ucms30/12/201817/6/2026
UCMS 1.4.7 has ?do=user_addpost CSRF.
ModificadaMedia (4.8)0.55%—Ucms Project Ucms30/12/201817/6/2026
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
ModificadaMedia (5.4)1.7%💥 ExploitFrog CMS Project Frog CMS25/12/201817/6/2026
Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.
ModificadaMedia (6.1)0.71%—Tp5cms Project Tp5cms29/11/201817/6/2026
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter.
ModificadaCrítica (9.8)1.5%—Tp5cms Project Tp5cms29/11/201817/6/2026
An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type.
ModificadaCrítica (9.8)1.1%—Arcms Project Arcms26/11/201817/6/2026
An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php.
ModificadaCrítica (9.8)1.5%—Arcms Project Arcms26/11/201817/6/2026
An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.
Orbitaley — Vulnerabilidades