Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.82% | — | Joyplus-cms Project Joyplus-cms | 22/7/2018 | 17/6/2026 | joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Phpcms Project Phpcms | 19/7/2018 | 17/6/2026 | libs\classes\attachment.class.php in PHPCMS 9.6.0 allows remote attackers to upload and execute arbitrary PHP code via a .txt?.php#.jpg URI in the SRC attribute of an IMG element within info[content] JSON data to the index.php?m=member&c=index&a=register URI. | |
| Modificada | Crítica (9.8) | 1.5% | — | Joyplus-cms Project Joyplus-cms | 18/7/2018 | 17/6/2026 | joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter. | |
| Modificada | Media (5.4) | 0.77% | — | Joyplus-cms Project Joyplus-cms | 18/7/2018 | 17/6/2026 | joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter. | |
| Modificada | Crítica (9.8) | 1.7% | — | Joyplus-cms Project Joyplus-cms | 17/7/2018 | 17/6/2026 | manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm value, and does not otherwise alter the flow of control. Consequently, one can upload and execute a .php file, a similar issue to CVE-2018-8766. | |
| Modificada | Alta (8.8) | 0.50% | — | Srcms Project Srcms | 15/7/2018 | 17/6/2026 | An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add a user account via admin.php?m=Admin&c=member&a=add. | |
| Modificada | Alta (8.8) | 0.65% | — | Srcms Project Srcms | 15/7/2018 | 17/6/2026 | An issue was discovered in SRCMS V2.3.1. There is a CSRF vulnerability that can add an admin account via admin.php?m=Admin&c=manager&a=add. | |
| Modificada | Alta (8.8) | 0.52% | — | Super CMS Project Super CMS | 12/7/2018 | 17/6/2026 | In waimai Super Cms 20150505, there is a CSRF vulnerability that can add an admin account via admin.php?m=Member&a=adminadd. | |
| Modificada | Alta (7.2) | 2.2% | — | Hongcms Project Hongcms | 29/6/2018 | 17/6/2026 | An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI. | |
| Modificada | Crítica (9.8) | 2.5% | — | Hycus CMS Project Hycus CMS | 29/6/2018 | 17/6/2026 | Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials. | |
| Modificada | Alta (7.2) | 2.6% | 💥 Exploit | Hongcms Project Hongcms | 27/6/2018 | 17/6/2026 | An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI. | |
| Modificada | Media (6.1) | 42% | — | Joyplus-cms Project Joyplus-cms | 27/6/2018 | 17/6/2026 | joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. | |
| Modificada | Media (6.5) | 0.48% | — | Akcms Project Akcms | 19/6/2018 | 17/6/2026 | An issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php. | |
| Modificada | Alta (8.8) | 0.57% | — | Akcms Project Akcms | 19/6/2018 | 17/6/2026 | An issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&job=newaccount URI. | |
| Modificada | Media (5.4) | 0.48% | — | Articlecms Project Articlecms | 13/6/2018 | 17/6/2026 | ArticleCMS through 2017-02-19 has XSS via an "add an article" action. | |
| Modificada | Media (6.1) | 0.71% | — | Hongcms Project Hongcms | 13/6/2018 | 17/6/2026 | system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code. | |
| Modificada | Alta (8.8) | 1.1% | — | Portfoliocms Project Portfoliocms | 13/6/2018 | 17/6/2026 | portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI. | |
| Modificada | Alta (7.2) | 1.1% | — | Portfoliocms Project Portfoliocms | 11/6/2018 | 17/6/2026 | portfolioCMS 1.0.5 has SQL Injection via the admin/portfolio.php preview parameter. | |
| Modificada | Media (5.4) | 5.6% | 💥 Exploit | Oecms Project Oecms | 11/6/2018 | 17/6/2026 | A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php. | |
| Modificada | Crítica (9.8) | 4.7% | — | Joyplus-cms Project Joyplus-cms | 7/6/2018 | 17/6/2026 | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a select substring. | |
| Modificada | Alta (8.8) | 0.60% | — | Cscms Project Cscms | 29/5/2018 | 17/6/2026 | An issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php allows remote attackers to change the administrator's username and password via /admin.php/sys/editpass_save. | |
| Modificada | Alta (7.2) | 1.4% | — | Frog CMS Project Frog CMS | 15/5/2018 | 17/6/2026 | An issue was discovered in Frog CMS 0.9.5. There is a file upload vulnerability via the admin/?/plugin/file_manager/upload URI, a similar issue to CVE-2014-4912. | |
| Modificada | Media (5.4) | 0.33% | — | Frogcms Project Frogcms | 8/5/2018 | 17/6/2026 | An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF. | |
| Modificada | Media (4.8) | 0.53% | — | Frogcms Project Frogcms | 30/4/2018 | 17/6/2026 | Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field. | |
| Modificada | Media (5.4) | 0.53% | — | Easycms Project Easycms | 28/4/2018 | 17/6/2026 | EasyCMS 1.3 is prone to Stored XSS when posting an article; four fields are affected: title, keyword, abstract, and content, as demonstrated by the /admin/index/index.html#listarticle URI. |