Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

824 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.36%—Concretecms Concrete CMS23/9/202117/6/2026
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team"
ModificadaMedia (6.5)0.44%—Concretecms Concrete CMS23/9/202117/6/2026
Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team"
ModificadaMedia (5.4)0.36%—Concretecms Concrete CMS23/9/202117/6/2026
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"
ModificadaAlta (7.8)0.88%—Kitesky Kitecms13/9/202117/6/2026
An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.
ModificadaAlta (8.8)0.55%—Kitesky Kitecms13/9/202117/6/2026
A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.
ModificadaCrítica (9.8)1.1%—Bluecms Project Bluecms8/9/202117/6/2026
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
ModificadaCrítica (9.8)1.9%—Dedecms27/8/202117/6/2026
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
ModificadaMedia (5.4)0.47%—Bigtreecms Bigtree CMS26/8/202117/6/2026
Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to admin/tags/create.
ModificadaAlta (8.8)0.84%—Dedecms24/8/202117/6/2026
The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
ModificadaAlta (7.2)1.8%—Aitecms18/8/202117/6/2026
SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php".
ModificadaCrítica (9.8)2.8%—Phome Empirecms17/8/202117/6/2026
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
ModificadaMedia (6.5)1.3%—Kitesky Kitecms12/8/202117/6/2026
A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter.
ModificadaMedia (6.1)0.94%—Get-simple Getsimplecms10/8/202117/6/2026
GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: "siteURL" parameter.
ModificadaMedia (6.5)0.44%—Wagecms Project Wage-cms6/8/202117/6/2026
A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.
ModificadaMedia (5.4)0.55%—Get-simple Getsimplecms6/8/202117/6/2026
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.
ModificadaAlta (7.2)3.7%—Concretecms Concrete CMS30/7/202117/6/2026
Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the…
ModificadaMedia (4.8)0.53%—Naviwebs Navigatecms26/7/202117/6/2026
Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
ModificadaMedia (4.8)0.53%—Naviwebs Navigatecms26/7/202117/6/2026
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
ModificadaCrítica (9.8)2.2%—Naviwebs Navigatecms26/7/202117/6/2026
In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database.
ModificadaCrítica (9.8)2.2%—Naviwebs Navigatecms26/7/202117/6/2026
In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database.
ModificadaCrítica (9.8)2.2%—Naviwebs Navigatecms26/7/202117/6/2026
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database.
ModificadaCrítica (9.8)2.5%—Naviwebs Navigatecms26/7/202117/6/2026
In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database.
ModificadaCrítica (9.8)2.2%—Naviwebs Navigatecms26/7/202117/6/2026
In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database.
ModificadaMedia (6.1)1.3%—Get-simple Getsimplecms23/6/202117/6/2026
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
ModificadaMedia (6.1)1.3%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php