Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.50% | — | Baijiacms Project Baijiacms | 27/4/2018 | 17/6/2026 | An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edituser, changing the administrator password via op=changepwd, or deleting an account via op=deleteuser. | |
| Modificada | Media (4.8) | 0.52% | — | Hongcms Project Hongcms | 26/4/2018 | 17/6/2026 | An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field. | |
| Modificada | Media (4.8) | 1.8% | 💥 Exploit | Frogcms Project Frogcms | 24/4/2018 | 17/6/2026 | Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings. | |
| Modificada | Media (4.8) | 0.52% | — | Frogcms Project Frogcms | 24/4/2018 | 17/6/2026 | Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout. | |
| Modificada | Media (4.8) | 0.54% | — | Frogcms Project Frogcms | 24/4/2018 | 17/6/2026 | Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet. | |
| Modificada | Media (4.8) | 0.54% | — | Frogcms Project Frogcms | 24/4/2018 | 17/6/2026 | Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata. | |
| Modificada | Alta (8.8) | 0.51% | — | Chemcms Project Chemcms | 22/4/2018 | 17/6/2026 | ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account. | |
| Modificada | Alta (8.8) | 0.52% | — | Wtcms Project Wtcms | 22/4/2018 | 17/6/2026 | WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI. | |
| Modificada | Alta (8.8) | 0.45% | — | Hongcms Project Hongcms | 22/4/2018 | 17/6/2026 | An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI. | |
| Modificada | Alta (8.8) | 0.49% | — | Baijiacms Project Baijiacms | 20/4/2018 | 17/6/2026 | baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account. | |
| Modificada | Media (5.3) | 0.85% | — | Baijiacms Project Baijiacms | 19/4/2018 | 17/6/2026 | baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request. | |
| Modificada | Media (6.1) | 0.65% | — | Xyhcms Project Xyhcms | 16/4/2018 | 17/6/2026 | An issue was discovered in XYHCMS 3.5. It has XSS via the test parameter to index.php. | |
| Modificada | Alta (8.8) | 0.47% | — | Xyhcms Project Xyhcms | 16/4/2018 | 17/6/2026 | An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the administrator role. | |
| Modificada | Media (4.8) | 0.62% | — | Joyplus-cms Project Joyplus-cms | 13/4/2018 | 17/6/2026 | joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request. | |
| Modificada | Media (4.8) | 0.62% | — | Joyplus-cms Project Joyplus-cms | 12/4/2018 | 17/6/2026 | joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter. | |
| Modificada | Media (5.3) | 1.5% | — | Joyplus-cms Project Joyplus-cms | 11/4/2018 | 17/6/2026 | joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI. | |
| Modificada | Media (4.8) | 0.52% | — | Frog CMS Project Frog CMS | 11/4/2018 | 17/6/2026 | Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen. | |
| Modificada | Media (4.8) | 0.52% | — | Frog CMS Project Frog CMS | 11/4/2018 | 17/6/2026 | Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter. | |
| Modificada | Alta (8.8) | 2.2% | 💥 Exploit | Frog CMS Project Frog CMS | 31/3/2018 | 17/6/2026 | An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an… | |
| Modificada | Media (5.4) | 0.78% | — | Covercms Project Covercms | 23/3/2018 | 17/6/2026 | CoverCMS v1.1.6 has XSS via the fourth input box to index.php, related to admina/mconfigs.inc.php. | |
| Modificada | Crítica (9.8) | 8.1% | 💥 Exploit | Frog CMS Project Frog CMS | 22/3/2018 | 17/6/2026 | An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation. | |
| Modificada | Media (4.8) | 0.62% | — | Joyplus-cms Project Joyplus-cms | 18/3/2018 | 17/6/2026 | joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter. | |
| Modificada | Crítica (9.8) | 3.3% | — | Joyplus-cms Project Joyplus-cms | 18/3/2018 | 17/6/2026 | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add. | |
| Modificada | Alta (8.8) | 0.63% | — | Joyplus-cms Project Joyplus-cms | 15/3/2018 | 17/6/2026 | joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request. | |
| Modificada | Media (6.1) | 0.99% | — | Quarx CMS Project Quarx CMS | 21/2/2018 | 17/6/2026 | Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Question), Pages (Title), Widgets (Name), and Menus (Name). |