Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.64%—Articlecms Project Articlecms23/11/201817/6/2026
ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.
ModificadaAlta (8.8)1.1%—Ucms Project Ucms22/11/201817/6/2026
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
ModificadaMedia (6.5)0.42%—Srcms Project Srcms16/11/201817/6/2026
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
ModificadaAlta (8.8)0.49%—Srcms Project Srcms16/11/201817/6/2026
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.
ModificadaMedia (4.8)0.67%—Wuzhi CMS Project Wuzhi CMS5/11/201817/6/2026
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.
ModificadaCrítica (9.8)1.3%—Laravelcms Project Laravelcms1/11/201817/6/2026
An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.
ModificadaMedia (6.1)0.71%—No-cms Project No-cms31/10/201817/6/2026
No-CMS 1.1.3 is prone to Persistent XSS via a contact_us name parameter, as demonstrated by the VG48Z5PqVWname parameter.
ModificadaAlta (8.8)0.49%—Dscms Project Dscms15/10/201817/6/2026
DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.
ModificadaCrítica (9.8)1.5%—Wuzhi CMS Project Wuzhi CMS1/10/201817/6/2026
A SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the /index.php?m=coupon&f=card&v=detail_listing URI.
ModificadaCrítica (9.8)1.7%—Horus CMS Project Horus CMS26/9/201817/6/2026
Horus CMS allows SQL Injection, as demonstrated by a request to the /busca or /home URI.
ModificadaMedia (6.1)0.83%—Weaselcms Project Weaselcms23/9/201817/6/2026
Multiple XSS vulnerabilities in WeaselCMS v0.3.6 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php because $_SERVER['PHP_SELF'] is mishandled.
ModificadaMedia (6.1)0.66%—Ucms Project Ucms21/9/201817/6/2026
An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.
ModificadaMedia (6.1)0.77%—Yiqicms Project Yiqicms16/9/201817/6/2026
An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be bypassed.
ModificadaAlta (8.8)0.96%—Ucms Project Ucms14/9/201817/6/2026
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
ModificadaCrítica (9.8)1.7%—Ucms Project Ucms14/9/201817/6/2026
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
ModificadaCrítica (9.8)1.1%—Ucms Project Ucms14/9/201817/6/2026
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.
ModificadaMedia (6.1)0.68%—Ucms Project Ucms14/9/201817/6/2026
UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.
ModificadaMedia (6.1)0.66%—Blogcms Project Blogcms10/9/201817/6/2026
BlogCMS through 2016-10-25 has XSS via a comment.
ModificadaMedia (4.8)0.53%—Victor CMS Project Victor CMS10/9/201817/6/2026
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the site name in the "Categories" menu.
ModificadaAlta (7.5)1.6%—Hongcms Project Hongcms10/9/201817/6/2026
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.
ModificadaMedia (6.1)0.71%—Baijiacms Project Baijiacms8/9/201817/6/2026
An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, aka "Non-standard use of the flash component."
ModificadaCrítica (9.8)1.2%—Baijiacms Project Baijiacms8/9/201817/6/2026
An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request.
ModificadaMedia (6.1)0.71%—Rejucms Project Rejucms7/9/201817/6/2026
rejucms 2.1 has XSS via the ucenter/cms_user_add.php u_name parameter.
ModificadaAlta (8.8)0.71%—Frogcms Project Frogcms4/9/201817/6/2026
Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.
ModificadaCrítica (9.8)1.1%—Bluecms Project Bluecms4/9/201817/6/2026
BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login.
Orbitaley — Vulnerabilidades