Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

824 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.4%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scriptiong (XSS) vulnerability in GetSimpleCMS <=3.3.15 via the timezone parameter to settings.php.
ModificadaMedia (6.1)1.4%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS <= 3.3.15 in admin/changedata.php via the redirect_url parameter and the headers_sent function.
ModificadaMedia (5.4)0.58%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.
ModificadaMedia (4.8)0.59%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in GetSimpleCMS 3.4.0a in admin/edit.php.
ModificadaMedia (4.8)0.51%—Get-simple Getsimplecms23/6/202117/6/2026
Cross Site Scripting vulnerability in GetSimpleCMS 3.3.16 in admin/upload.php by adding comments or jpg and other file header information to the content of xla, pages, and gzip files,
ModificadaAlta (7.2)7.5%💥 ExploitGet-simple Getsimplecms23/6/202117/6/2026
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
ModificadaAlta (7.5)1.5%—5none Nonecms22/6/202117/6/2026
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
ModificadaAlta (7.5)1.5%—5none Nonecms22/6/202117/6/2026
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
ModificadaCrítica (9.8)1.7%—Dedecms16/6/202117/6/2026
SQL Injection vulnerability in DedeCMS 5.7 via mdescription parameter to member/ajax_membergroup.php.
ModificadaAlta (8.8)1.8%—Bigtreecms Bigtree CMS1/6/202117/6/2026
A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create a New Setting' function.
ModificadaMedia (5.4)0.60%—Bigtreecms Bigtree CMS1/6/202117/6/2026
A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/admin/pages/update.
ModificadaAlta (8.8)1.4%—Bigtreecms Bigtree CMS1/6/202117/6/2026
A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New Feed' function.
ModificadaAlta (8.8)1.2%—Dedecms15/5/202117/6/2026
DedeCMS V5.7 SP2 contains a CSRF vulnerability that allows a remote attacker to send a malicious request to to the web manager allowing remote code execution.
ModificadaMedia (5.4)0.55%—Dedecms15/5/202117/6/2026
A XSS Vulnerability in /uploads/dede/action_search.php in DedeCMS V5.7 SP2 allows an authenticated user to execute remote arbitrary code via the keyword parameter.
ModificadaCrítica (9.8)1.3%—Articlecms Project Articlecms13/5/202117/6/2026
A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
ModificadaCrítica (9.8)1.3%—Articlecms Project Articlecms13/5/202117/6/2026
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.
ModificadaMedia (6.1)0.36%—5none Nonecms10/5/202117/6/2026
NoneCMS v1.3 has a CSRF vulnerability in public/index.php/admin/nav/add.html, as demonstrated by adding a navigation column which can be injected with arbitrary web script or HTML via the name parameter to launch a stored XSS attack.
ModificadaMedia (5.4)0.79%—5none Nonecms10/5/202117/6/2026
Cross-site scripting (XSS) vulnerability in admin/article/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
ModificadaMedia (5.4)0.79%—5none Nonecms10/5/202117/6/2026
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
ModificadaMedia (6.1)0.94%—5none Nonecms10/5/202117/6/2026
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter.
ModificadaMedia (5.4)0.86%—Concretecms Concrete CMS18/3/202117/6/2026
Concrete CMS (formerly concrete5) before 8.5.5 allows remote authenticated users to conduct XSS attacks via a crafted survey block. This requires at least Editor privileges.
ModificadaMedia (5.3)1.8%—Apostrophecms Sanitize-html8/2/202117/6/2026
Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHostnames" option when the "allowIframeRelativeUrls" is set to true, which allows attackers to bypass hostname whitelist for iframe element, related using an src value that starts with "/\\example.com".
ModificadaMedia (5.3)2.0%—Apostrophecms Sanitize-html8/2/202117/6/2026
Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which could allow an attacker to bypass hostname whitelist validation set by the "allowedIframeHostnames" option.
ModificadaMedia (4.8)3.0%💥 ExploitConcretecms Concrete CMS8/1/202117/6/2026
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
ModificadaCrítica (9.8)1.0%—Yunyecms21/12/202017/6/2026
SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.