Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.4% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php. | |
| Modificada | Media (6.1) | 1.4% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function. | |
| Modificada | Media (5.4) | 0.58% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets. | |
| Modificada | Media (4.8) | 0.59% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php. | |
| Modificada | Media (4.8) | 0.51% | — | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files, | |
| Modificada | Alta (7.2) | 7.5% | 💥 Exploit | Get-simple Getsimplecms | 23/6/2021 | 17/6/2026 | Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess. | |
| Modificada | Alta (7.5) | 1.5% | — | 5none Nonecms | 22/6/2021 | 17/6/2026 | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor". | |
| Modificada | Alta (7.5) | 1.5% | — | 5none Nonecms | 22/6/2021 | 17/6/2026 | Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php". | |
| Modificada | Crítica (9.8) | 1.7% | — | Dedecms | 16/6/2021 | 17/6/2026 | SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php. | |
| Modificada | Alta (8.8) | 1.8% | — | Bigtreecms Bigtree CMS | 1/6/2021 | 17/6/2026 | A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create a New Setting' function. | |
| Modificada | Media (5.4) | 0.60% | — | Bigtreecms Bigtree CMS | 1/6/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/admin/pages/update. | |
| Modificada | Alta (8.8) | 1.4% | — | Bigtreecms Bigtree CMS | 1/6/2021 | 17/6/2026 | A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New Feed' function. | |
| Modificada | Alta (8.8) | 1.2% | — | Dedecms | 15/5/2021 | 17/6/2026 | DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution. | |
| Modificada | Media (5.4) | 0.55% | — | Dedecms | 15/5/2021 | 17/6/2026 | A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter. | |
| Modificada | Crítica (9.8) | 1.3% | — | Articlecms Project Articlecms | 13/5/2021 | 17/6/2026 | A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell. | |
| Modificada | Crítica (9.8) | 1.3% | — | Articlecms Project Articlecms | 13/5/2021 | 17/6/2026 | File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code. | |
| Modificada | Media (6.1) | 0.36% | — | 5none Nonecms | 10/5/2021 | 17/6/2026 | NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML via the name parameter to launch a stored XSS attack. | |
| Modificada | Media (5.4) | 0.79% | — | 5none Nonecms | 10/5/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (5.4) | 0.79% | — | 5none Nonecms | 10/5/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter. | |
| Modificada | Media (6.1) | 0.94% | — | 5none Nonecms | 10/5/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter. | |
| Modificada | Media (5.4) | 0.86% | — | Concretecms Concrete CMS | 18/3/2021 | 17/6/2026 | Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges. | |
| Modificada | Media (5.3) | 1.8% | — | Apostrophecms Sanitize-html | 8/2/2021 | 17/6/2026 | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com". | |
| Modificada | Media (5.3) | 2.0% | — | Apostrophecms Sanitize-html | 8/2/2021 | 17/6/2026 | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option. | |
| Modificada | Media (4.8) | 3.0% | 💥 Exploit | Concretecms Concrete CMS | 8/1/2021 | 17/6/2026 | The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI. | |
| Modificada | Crítica (9.8) | 1.0% | — | Yunyecms | 21/12/2020 | 17/6/2026 | SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter. |