Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 2.8% | 💥 Exploit | Dedecms | 23/10/2018 | 17/6/2026 | DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php. | |
| Modificada | Media (6.1) | 0.73% | — | Dedecms | 22/10/2018 | 17/6/2026 | Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter. | |
| Modificada | Media (6.1) | 0.73% | — | Dedecms | 22/10/2018 | 17/6/2026 | DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter. | |
| Modificada | Media (5.4) | 1.1% | — | Bigtreecms Bigtree CMS | 19/10/2018 | 17/6/2026 | A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation could allow an attacker to hijack an admin session. | |
| Modificada | Media (6.1) | 3.6% | 💥 Exploit | Bigtreecms Bigtree CMS | 16/10/2018 | 17/6/2026 | In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area). | |
| Modificada | Crítica (9.8) | 1.5% | — | Bagesoft Bagecms | 11/10/2018 | 17/6/2026 | An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI. | |
| Modificada | Alta (7.5) | 1.6% | — | Bagesoft Bagecms | 11/10/2018 | 17/6/2026 | An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI. | |
| Modificada | Alta (8.8) | 0.81% | — | Finecms | 9/10/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attackers to change the administrator's password. | |
| Modificada | Alta (8.8) | 1.5% | — | Phome Empirecms | 9/10/2018 | 17/6/2026 | EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users. | |
| Modificada | Alta (8.1) | 1.9% | — | Bigtreecms Bigtree CMS | 23/9/2018 | 17/6/2026 | BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\ URI. | |
| Modificada | Media (6.1) | 0.68% | — | Dedecms | 21/9/2018 | 17/6/2026 | DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php. | |
| Modificada | Alta (7.2) | 2.3% | — | Dedecms | 21/9/2018 | 17/6/2026 | DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring. | |
| Modificada | Alta (8.8) | 1.9% | — | Dedecms | 19/9/2018 | 17/6/2026 | XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized by attackers to create script file to obtain webshell | |
| Modificada | Alta (7.5) | 2.3% | — | Bigtreecms Bigtree CMS | 14/9/2018 | 17/6/2026 | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php. | |
| Modificada | Media (5.5) | 1.7% | — | Littlecms Little CMS Color EngineCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 4/9/2018 | 17/6/2026 | Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile. | |
| Modificada | Crítica (9.8) | 1.1% | — | Bluecms Project Bluecms | 4/9/2018 | 17/6/2026 | BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login. | |
| Modificada | Alta (8.8) | 0.52% | — | Phome Empirecms | 2/9/2018 | 17/6/2026 | An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser. | |
| Modificada | Crítica (9.8) | 1.6% | — | Phpkaiyuancms Phpopensourcecms | 31/8/2018 | 17/6/2026 | phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter. | |
| Modificada | Alta (8.8) | 0.52% | — | Bagesoft Bagecms | 24/7/2018 | 17/6/2026 | index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account. | |
| Modificada | Alta (7.2) | 1.0% | — | Concretecms Concrete CMS | 9/7/2018 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page. | |
| Modificada | Crítica (9.8) | 1.4% | — | Onefilecms | 3/7/2018 | 17/6/2026 | onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file. | |
| Modificada | Media (6.5) | 0.78% | — | Onefilecms | 3/7/2018 | 17/6/2026 | onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI. | |
| Modificada | Alta (8.8) | 1.2% | — | Onefilecms | 29/6/2018 | 17/6/2026 | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen. | |
| Modificada | Alta (8.8) | 1.2% | — | Onefilecms | 29/6/2018 | 17/6/2026 | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen. | |
| Modificada | Crítica (9.8) | 1.2% | — | Onefilecms | 29/6/2018 | 17/6/2026 | onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields. |