Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Concretecms Concrete CMS | 23/9/2021 | 17/6/2026 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security Research Team" | |
| Modificada | Media (6.5) | 0.44% | — | Concretecms Concrete CMS | 23/9/2021 | 17/6/2026 | Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be deleted.Credit for discovery: "Solar Security Research Team" | |
| Modificada | Media (5.4) | 0.36% | — | Concretecms Concrete CMS | 23/9/2021 | 17/6/2026 | A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team" | |
| Modificada | Alta (7.8) | 0.88% | — | Kitesky Kitecms | 13/9/2021 | 17/6/2026 | An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file. | |
| Modificada | Alta (8.8) | 0.55% | — | Kitesky Kitecms | 13/9/2021 | 17/6/2026 | A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account. | |
| Modificada | Crítica (9.8) | 1.1% | — | Bluecms Project Bluecms | 8/9/2021 | 17/6/2026 | BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dedecms | 27/8/2021 | 17/6/2026 | An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format. | |
| Modificada | Media (5.4) | 0.47% | — | Bigtreecms Bigtree CMS | 26/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to admin/tags/create. | |
| Modificada | Alta (8.8) | 0.84% | — | Dedecms | 24/8/2021 | 17/6/2026 | The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control. | |
| Modificada | Alta (7.2) | 1.8% | — | Aitecms | 18/8/2021 | 17/6/2026 | SQL Injection in AiteCMS v1.0 allows remote attackers to execute arbitrary code via the component "aitecms/login/diy_list.php". | |
| Modificada | Crítica (9.8) | 2.8% | — | Phome Empirecms | 17/8/2021 | 17/6/2026 | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file. | |
| Modificada | Media (6.5) | 1.3% | — | Kitesky Kitecms | 12/8/2021 | 17/6/2026 | A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the path parameter to index.php/admin/Template/fileedit, with PHP code in the html parameter. | |
| Modificada | Media (6.1) | 0.94% | — | Get-simple Getsimplecms | 10/8/2021 | 17/6/2026 | GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settings.php Website URL: "siteURL" parameter. | |
| Modificada | Media (6.5) | 0.44% | — | Wagecms Project Wage-cms | 6/8/2021 | 17/6/2026 | A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users. | |
| Modificada | Media (5.4) | 0.55% | — | Get-simple Getsimplecms | 6/8/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module. | |
| Modificada | Alta (7.2) | 3.7% | — | Concretecms Concrete CMS | 30/7/2021 | 17/6/2026 | Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/dashboard/system/environment/logging.php Logging::update_logging() method. User input passed through the logFile request parameter is not properly sanitized before being used in a call to the… | |
| Modificada | Media (4.8) | 0.53% | — | Naviwebs Navigatecms | 26/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature. | |
| Modificada | Media (4.8) | 0.53% | — | Naviwebs Navigatecms | 26/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature. | |
| Modificada | Crítica (9.8) | 2.2% | — | Naviwebs Navigatecms | 26/7/2021 | 17/6/2026 | In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, which results in arbitrary sql query execution in the backend database. | |
| Modificada | Crítica (9.8) | 2.2% | — | Naviwebs Navigatecms | 26/7/2021 | 17/6/2026 | In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `children_order`, which results in arbitrary sql query execution in the backend database. | |
| Modificada | Crítica (9.8) | 2.2% | — | Naviwebs Navigatecms | 26/7/2021 | 17/6/2026 | In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` through a post request, which results in arbitrary sql query execution in the backend database. | |
| Modificada | Crítica (9.8) | 2.5% | — | Naviwebs Navigatecms | 26/7/2021 | 17/6/2026 | In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `template-properties-order`, which results in arbitrary sql query execution in the backend database. | |
| Modificada | Crítica (9.8) | 2.2% | — | Naviwebs Navigatecms | 26/7/2021 | 17/6/2026 | In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-order` through a post request, which results in arbitrary sql query execution in the backend database. | |
| Modificada | Media (6.1) | 1.3% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting vulnerability in GetSimpleCMS <=3.3.15 via the (1) sitename, (2) username, and (3) email parameters to /admin/setup.php |