Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.83% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters. | |
| Modificada | Media (6.1) | 0.83% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filename`, `mid`, `userid`, and `templet' parameters. | |
| Modificada | Media (6.1) | 0.83% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component mychannel_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters. | |
| Modificada | Media (5.4) | 0.58% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters. | |
| Modificada | Media (5.4) | 0.58% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component select_media.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters. | |
| Modificada | Media (5.4) | 0.58% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tags_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters. | |
| Modificada | Media (5.4) | 0.58% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters. | |
| Modificada | Media (6.1) | 0.83% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters. | |
| Modificada | Media (5.4) | 0.58% | — | Dedecms | 22/10/2021 | 17/6/2026 | DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters. | |
| Modificada | Media (5.4) | 0.58% | — | Jeecms X | 7/10/2021 | 17/6/2026 | JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Crítica (9.8) | 1.2% | — | Concretecms Concrete CMS | 7/10/2021 | 17/6/2026 | A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.CVSSv2.0 AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N | |
| Modificada | Media (5.4) | 0.50% | — | Jeecms | 30/9/2021 | 17/6/2026 | JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the commentText parameter. | |
| Modificada | Crítica (9.8) | 1.1% | — | Flamecms Project Flamecms | 30/9/2021 | 17/6/2026 | FlameCMS 3.3.5 contains a time-based blind SQL injection vulnerability in /account/register.php. | |
| Modificada | Crítica (9.8) | 0.99% | — | Flamecms Project Flamecms | 30/9/2021 | 17/6/2026 | FlameCMS 3.3.5 contains a SQL injection vulnerability in /master/article.php via the "Id" parameter. | |
| Modificada | Media (6.4) | 0.54% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A user with permissions to upload files from external sites can upload a URL that redirects to an internal resource of any file type. The redirect is followed and loads the contents of the file from the… | |
| Modificada | Alta (8.8) | 0.50% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on the ccm/calendar/dialogs/event/add/save endpoint. | |
| Modificada | Media (6.1) | 0.65% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the website field. | |
| Modificada | Media (6.1) | 0.65% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments. | |
| Modificada | Alta (7.5) | 1.4% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass. | |
| Modificada | Alta (7.5) | 1.5% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF. | |
| Modificada | Crítica (9.8) | 1.6% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression. | |
| Modificada | Alta (8.8) | 2.5% | — | Concretecms Concrete CMS | 27/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter. | |
| Modificada | Crítica (9.1) | 1.3% | — | Concretecms Concrete CMS | 24/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method). | |
| Modificada | Media (5.4) | 0.52% | — | Concretecms Concrete CMS | 24/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text. | |
| Modificada | Alta (7.2) | 2.1% | — | Concretecms Concrete CMS | 24/9/2021 | 17/6/2026 | An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution. |