Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Wtcms Project Wtcms | 18/2/2019 | 17/6/2026 | An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type: image/gif" header. | |
| Modificada | Media (6.5) | 1.5% | — | Hongcms Project Hongcms | 17/2/2019 | 17/6/2026 | HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI. | |
| Modificada | Media (6.1) | 0.83% | — | Frog CMS Project Frog CMS | 11/2/2019 | 17/6/2026 | admin/?/plugin/file_manager in Frog CMS 0.9.5 allows XSS by creating a new file containing a crafted attribute of an IMG element. | |
| Modificada | Media (5.4) | 0.64% | — | Frog CMS Project Frog CMS | 11/2/2019 | 17/6/2026 | Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit/1 Body field. | |
| Modificada | Alta (7.5) | 1.5% | — | Frog CMS Project Frog CMS | 11/2/2019 | 17/6/2026 | Frog CMS 0.9.5 provides a directory listing for a /public request. | |
| Modificada | Alta (7.2) | 2.1% | — | Frog CMS Project Frog CMS | 11/2/2019 | 17/6/2026 | admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI. | |
| Modificada | Media (5.4) | 0.64% | — | Frog CMS Project Frog CMS | 11/2/2019 | 17/6/2026 | Frog CMS 0.9.5 has XSS via the admin/?/layout/edit/1 Body field. | |
| Modificada | Alta (7.2) | 2.1% | — | Frog CMS Project Frog CMS | 11/2/2019 | 17/6/2026 | Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines. | |
| Modificada | Alta (7.2) | 2.1% | — | Frog CMS Project Frog CMS | 11/2/2019 | 17/6/2026 | Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI. | |
| Modificada | Crítica (9.8) | 1.5% | — | Baijiacms Project Baijiacms | 7/2/2019 | 17/6/2026 | An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request. | |
| Modificada | Media (6.1) | 0.68% | — | Frog CMS Project Frog CMS | 12/1/2019 | 17/6/2026 | Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI). | |
| Modificada | Media (4.8) | 0.58% | — | Frog CMS Project Frog CMS | 9/1/2019 | 17/6/2026 | Frog CMS 0.9.5 has XSS in the admin/?/page/edit/1 body field. | |
| Modificada | Media (4.8) | 0.56% | — | No-cms Project No-cms | 31/12/2018 | 17/6/2026 | No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article "keyword" parameter. | |
| Modificada | Media (4.8) | 0.56% | — | No-cms Project No-cms | 31/12/2018 | 17/6/2026 | No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter. | |
| Modificada | Media (4.8) | 0.56% | — | Frogcms Project Frogcms | 31/12/2018 | 17/6/2026 | FROG CMS 0.9.5 has XSS via the admin/?/snippet/add name parameter, which is mishandled during an edit action, a related issue to CVE-2018-10319. | |
| Modificada | Media (4.8) | 0.56% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action. | |
| Modificada | Media (6.1) | 0.71% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action. | |
| Modificada | Alta (8.8) | 1.5% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action. | |
| Modificada | Alta (8.8) | 0.53% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | UCMS 1.4.7 has ?do=user_addpost CSRF. | |
| Modificada | Media (4.8) | 0.55% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action. | |
| Modificada | Media (5.4) | 1.7% | 💥 Exploit | Frog CMS Project Frog CMS | 25/12/2018 | 17/6/2026 | Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI. | |
| Modificada | Media (6.1) | 0.71% | — | Tp5cms Project Tp5cms | 29/11/2018 | 17/6/2026 | An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Tp5cms Project Tp5cms | 29/11/2018 | 17/6/2026 | An issue was discovered in tp5cms through 2017-05-25. admin.php/upload/picture.html allows remote attackers to execute arbitrary PHP code by uploading a .php file with the image/jpeg content type. | |
| Modificada | Crítica (9.8) | 1.1% | — | Arcms Project Arcms | 26/11/2018 | 17/6/2026 | An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Arcms Project Arcms | 26/11/2018 | 17/6/2026 | An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images. |