Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.64%—Frog CMS Project Frog CMS3/9/201817/6/2026
Frog CMS 0.9.5 has stored XSS via /admin/?/plugin/comment/settings.
ModificadaMedia (4.9)1.1%💥 PoCFrog CMS Project Frog CMS3/9/201817/6/2026
Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save.
ModificadaCrítica (9.8)1.4%—Weaselcms Project Weaselcms2/9/201817/6/2026
There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png content type is used.
ModificadaMedia (6.1)0.86%—Wuzhi CMS Project Wuzhi CMS2/9/201817/6/2026
WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
ModificadaMedia (6.1)0.86%—Wuzhi CMS Project Wuzhi CMS2/9/201817/6/2026
WUZHI CMS 4.1.0 has XSS via the index.php?m=link&f=index&v=add form[remark] parameter.
ModificadaMedia (4.8)0.56%—Chemcms Project Chemcms2/9/201817/6/2026
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
ModificadaCrítica (9.8)1.5%—Wuzhi CMS Project Wuzhi CMS27/8/201817/6/2026
A SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing keyValue parameter.
ModificadaCrítica (9.8)1.5%—Wuzhi CMS Project Wuzhi CMS27/8/201817/6/2026
A SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing keywords parameter.
ModificadaAlta (8.8)0.59%—Flexocms Project Flexo CMS25/8/201817/6/2026
An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user/add.
ModificadaMedia (4.3)0.36%—Portfoliocms Project Portfoliocms25/8/201817/6/2026
An issue was discovered in portfolioCMS 1.0.5. There is CSRF to update the website settings via admin/aboutus.php.
ModificadaAlta (8.8)0.47%—Portfoliocms Project Portfoliocms25/8/201817/6/2026
An issue was discovered in portfolioCMS 1.0.5. There is CSRF to create new pages via admin/portfolio.php?newpage=true.
ModificadaAlta (8.8)0.73%—Fledrcms Project Fledrcms25/8/201817/6/2026
An issue was discovered in fledrCMS through 2014-02-03. There is a CSRF vulnerability that can change the administrator's password via index.php?p=done&savedata=1.
ModificadaMedia (6.1)0.65%—Victor CMS Project Victor CMS21/8/201817/6/2026
An issue was discovered in Victor CMS through 2018-05-10. There is XSS via the Author field of the "Leave a Comment" screen.
ModificadaAlta (8.8)0.48%—Tp5cms Project Tp5cms20/8/201817/6/2026
tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.
ModificadaMedia (6.1)0.68%—Tp5cms Project Tp5cms20/8/201817/6/2026
tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter.
ModificadaAlta (8.8)0.57%—Simple-cms Project Simple CMS20/8/201817/6/2026
An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can also be exploited via CSRF.
ModificadaAlta (8.8)0.46%—Simple-cms Project Simple CMS20/8/201817/6/2026
An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8.
ModificadaAlta (8.8)0.52%—Weaselcms Project Weaselcms5/8/201817/6/2026
An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI.
ModificadaAlta (8.8)0.52%—Weaselcms Project Weaselcms5/8/201817/6/2026
An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php.
ModificadaMedia (5.4)0.51%—Weaselcms Project Weaselcms3/8/201817/6/2026
An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywords on the SETTINGS page.
ModificadaMedia (6.1)0.71%—Rejucms Project Rejucms2/8/201817/6/2026
rejucms 2.1 has stored XSS via the admin/book.php content parameter.
ModificadaMedia (6.1)0.71%—Xycms Project Xycms28/7/201817/6/2026
system/edit_book.php in XYCMS 1.7 has stored XSS via a crafted add_do.php request, related to add_book.php.
ModificadaCrítica (9.8)1.6%—Golemcms Project Golemcms24/7/201817/6/2026
GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by inserting this code into the "Database Information" "Table prefix" form field, or obtain sensitive information via a direct request for install/install.sql.
ModificadaCrítica (9.8)2.0%—Wuzhi CMS Project Wuzhi CMS23/7/201817/6/2026
A SQL injection was discovered in WUZHI CMS 4.1.0 that allows remote attackers to inject a malicious SQL statement via the index.php?m=promote&f=index&v=search keywords parameter.
ModificadaMedia (6.1)1.1%—Wuzhi CMS Project Wuzhi CMS23/7/201817/6/2026
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[content] parameter to the index.php?m=feedback&f=index&v=contact URI.
Orbitaley — Vulnerabilidades