Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

824 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)3.6%💥 ExploitDedecms22/10/202017/6/2026
A Cross Site Scripting (XSS) issue was discovered in the search feature of DedeCMS v.5.8 that allows malicious users to inject code into web pages, and other users will be affected when viewing web pages.
ModificadaCrítica (9.1)2.1%—Get-simple Getsimplecms2/10/202017/6/2026
GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php
ModificadaAlta (7.2)2.0%—Concretecms Concrete CMS4/9/202017/6/2026
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.
ModificadaMedia (5.4)0.53%—Naviwebs Navigatecms26/8/202017/6/2026
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
ModificadaMedia (5.4)0.53%—Naviwebs Navigatecms26/8/202017/6/2026
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."
ModificadaMedia (5.4)0.55%—Naviwebs Navigatecms26/8/202017/6/2026
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
ModificadaMedia (5.4)0.53%—Naviwebs Navigatecms26/8/202017/6/2026
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."
ModificadaAlta (8.8)16%💥 ExploitRitecms18/8/202017/6/2026
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.
ModificadaAlta (7.2)2.9%—Concretecms Concrete CMS28/7/202017/6/2026
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
ModificadaMedia (5.3)0.94%—Concretecms Concrete CMS22/6/202017/6/2026
Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
ModificadaCrítica (9.8)1.2%—Naviwebs Navigatecms15/6/202017/6/2026
The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.
ModificadaMedia (6.1)0.84%—Apostrophecms Sanitize-html23/1/202017/6/2026
sanitize-html before 1.4.3 has XSS.
ModificadaMedia (6.1)0.69%—Concretecms Concrete CMS14/1/202016/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
ModificadaAlta (8.8)57%💥 ExploitDedecms6/1/202017/6/2026
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
ModificadaAlta (8.8)1.1%—Eyecomms Eyecms7/11/201917/6/2026
A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidate's account (by also exploiting CVE-2019-17604) via a modified candidate id and an additional password parameter. The outcome is that the password of this other candidate is changed.
ModificadaMedia (4.3)0.62%—Eyecomms Eyecms7/11/201917/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to change other candidates' personal information (first name, last name, email, CV, phone number, and all other personal information) by changing the value of the candidate id (the id parameter).
ModificadaMedia (6.5)0.53%—5none Nonecms23/9/201917/6/2026
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user.
ModificadaCrítica (9.8)5.0%—Flamecms Project Flamecms14/9/201917/6/2026
FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
ModificadaAlta (8.8)0.65%—Phpcoo Oecms18/7/201917/6/2026
OECMS v4.3.R60321 and v4.3 later is affected by: Cross Site Request Forgery (CSRF). The impact is: The victim clicks on adding an administrator account. The component is: admincp.php. The attack vector is: network connectivity. The fixed version is: v4.3.
ModificadaAlta (7.2)1.6%—Elitecms Elite CMS3/7/201917/6/2026
An issue was discovered in Elite CMS Pro 2.01. In /admin/add_sidebar.php, the ?page= parameter is vulnerable to SQL injection.
ModificadaMedia (4.8)0.99%—Concretecms Concrete CMS17/6/201917/6/2026
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
ModificadaAlta (7.2)2.2%—Phome Empirecms7/6/201917/6/2026
admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php.
ModificadaMedia (4.8)0.92%—Phome Empirecms7/6/201917/6/2026
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
ModificadaMedia (6.1)0.83%—Phome Empirecms27/5/201917/6/2026
EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php.
ModificadaMedia (6.1)0.41%—Phome Empirecms27/5/201917/6/2026
EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page.