Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

824 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)2.8%💥 ExploitDedecms23/10/201817/6/2026
DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php.
ModificadaMedia (6.1)0.73%—Dedecms22/10/201817/6/2026
Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.
ModificadaMedia (6.1)0.73%—Dedecms22/10/201817/6/2026
DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.
ModificadaMedia (5.4)1.1%—Bigtreecms Bigtree CMS19/10/201817/6/2026
A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation could allow an attacker to hijack an admin session.
ModificadaMedia (6.1)3.6%💥 ExploitBigtreecms Bigtree CMS16/10/201817/6/2026
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area).
ModificadaCrítica (9.8)1.5%—Bagesoft Bagecms11/10/201817/6/2026
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.
ModificadaAlta (7.5)1.6%—Bagesoft Bagecms11/10/201817/6/2026
An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.
ModificadaAlta (8.8)0.81%—Finecms9/10/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attackers to change the administrator's password.
ModificadaAlta (8.8)1.5%—Phome Empirecms9/10/201817/6/2026
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
ModificadaAlta (8.1)1.9%—Bigtreecms Bigtree CMS23/9/201817/6/2026
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI.
ModificadaMedia (6.1)0.68%—Dedecms21/9/201817/6/2026
DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.
ModificadaAlta (7.2)2.3%—Dedecms21/9/201817/6/2026
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.
ModificadaAlta (8.8)1.9%—Dedecms19/9/201817/6/2026
XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell
ModificadaAlta (7.5)2.3%—Bigtreecms Bigtree CMS14/9/201817/6/2026
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php.
ModificadaMedia (5.5)1.7%—Littlecms Little CMS Color EngineCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+24/9/201817/6/2026
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
ModificadaCrítica (9.8)1.1%—Bluecms Project Bluecms4/9/201817/6/2026
BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login.
ModificadaAlta (8.8)0.52%—Phome Empirecms2/9/201817/6/2026
An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.
ModificadaCrítica (9.8)1.6%—Phpkaiyuancms Phpopensourcecms31/8/201817/6/2026
phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.
ModificadaAlta (8.8)0.52%—Bagesoft Bagecms24/7/201817/6/2026
index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.
ModificadaAlta (7.2)1.0%—Concretecms Concrete CMS9/7/201817/6/2026
A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
ModificadaCrítica (9.8)1.4%—Onefilecms3/7/201817/6/2026
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file.
ModificadaMedia (6.5)0.78%—Onefilecms3/7/201817/6/2026
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI.
ModificadaAlta (8.8)1.2%—Onefilecms29/6/201817/6/2026
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.
ModificadaAlta (8.8)1.2%—Onefilecms29/6/201817/6/2026
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen.
ModificadaCrítica (9.8)1.2%—Onefilecms29/6/201817/6/2026
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.