Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.59% | — | Xjyunjing Yunjing Content Management System | 31/10/2022 | 17/6/2026 | A vulnerability classified as critical was found in Yunjing CMS. This vulnerability affects unknown code of the file /index/user/upload_img.html. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.4) | 0.70% | — | Adobe WEB Content Management Core Components | 10/8/2022 | 17/6/2026 | Adobe Experience Manager Core Components version 2.20.6 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.… | |
| Modificada | Media (5.4) | 0.50% | — | College Website Content Management System Project College Website Content Management System | 5/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields. | |
| Modificada | Media (4.8) | 0.54% | — | Totaljs Content Management System | 1/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Name text field when creating a new page. | |
| Modificada | Media (5.4) | 0.57% | — | Macrob7 Macs Framework Content Management System Project Macrob7 Macs Framework Content Management System | 22/10/2021 | 17/6/2026 | Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field. | |
| Modificada | Media (5.4) | 0.57% | — | Ericsson Enterprise Content Management | 17/9/2021 | 17/6/2026 | In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover. | |
| Modificada | Alta (8) | 1.1% | — | Ericsson Enterprise Content Management | 17/9/2021 | 17/6/2026 | In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection. | |
| Modificada | Media (6.1) | 0.84% | — | Content Management System Project Content Management System | 22/7/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter to content_management_system\admin\new_content.php | |
| Modificada | Alta (8.8) | 1.7% | — | Atlassian Alfresco Enterprise Content Management | 19/2/2021 | 17/6/2026 | An issue was discovered in Alfresco Enterprise Content Management (ECM) before 6.2.1. A user with privileges to edit a FreeMarker template (e.g., a webscript) may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running Alfresco. | |
| Modificada | Crítica (9.8) | 2.3% | — | Vignette Content Management | 31/1/2019 | 17/6/2026 | In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the vgn/ccb/user/mgmt/user/edit/0,1628,0,00.html?uid=admin HTML source code, and then creating a privileged user account. NOTE: this product is discontinued. | |
| Modificada | Media (4.8) | 0.63% | — | Generic Content Management System Project Generic Content Management System | 30/12/2018 | 17/6/2026 | Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/users.php user ID. | |
| Modificada | Media (4.8) | 0.64% | — | Generic Content Management System Project Generic Content Management System | 30/12/2018 | 17/6/2026 | Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 has XSS via the Administrator/add_pictures.php article ID. | |
| Modificada | Crítica (9.8) | 1.6% | — | Generic Content Management System Project Generic Content Management System | 28/12/2018 | 17/6/2026 | user/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authentication bypass. | |
| Modificada | Crítica (9.8) | 1.6% | — | Generic Content Management System Project Generic Content Management System | 28/12/2018 | 17/6/2026 | Administrator/index.php in Ivan Cordoba Generic Content Management System (CMS) through 2018-04-28 allows SQL injection for authentication bypass. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mushroom Content Management System Project Mushroom Content Management System | 30/9/2018 | 17/6/2026 | An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, resulting in a SQL injection vulnerability in getChannel() in the ChannelService.java file. | |
| Modificada | Crítica (9.8) | 1.9% | — | Ektron Content Management System | 30/10/2017 | 16/6/2026 | The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attackers to read arbitrary files and consequently bypass authentication, modify viewstate, cause a denial of service, or possibly have… | |
| Modificada | Crítica (9.8) | 68% | 💥 Exploit | Ektron Content Management System | 30/10/2017 | 16/6/2026 | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remote attackers to execute arbitrary code with NETWORK SERVICE privileges via crafted XSL data. | |
| Modificada | Media (5.4) | 0.52% | — | Aspsource Simple ASC Content Management System | 28/10/2017 | 17/6/2026 | Simple ASC Content Management System v1.2 has XSS in the location field in the sign function, related to guestbook.asp, formgb.asp, and msggb.asp. | |
| Modificada | Media (6.1) | 0.76% | — | Ektron Content Management System | 25/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the rptStatus parameter in a Report action to WorkArea/SelectUserGroup.aspx. | |
| Modificada | Media (6.1) | 0.89% | — | Ektron Content Management System | 3/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the ContType parameter in a ViewContentByCategory action to WorkArea/content.aspx. | |
| Modificada | Baja (3.5) | 1.5% | — | Ektron Content Management System | 9/6/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Test/WorkArea/workarea.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.114) allow remote authenticated users to inject arbitrary web script or HTML via the (1) page, (2) action, (3) folder_id, or (4) LangType parameter. | |
| Modificada | Media (5.8) | 2.3% | 💥 Exploit | Ektron Content Management System | 9/6/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content Management System (CMS) before 9.10 SP1 (Build 9.1.0.184.1.120) allows remote attackers to hijack the authentication of content administrators for requests that delete content via a delete action. | |
| Modificada | Media (6.8) | 2.4% | — | Ektron Content Management System | 14/2/2015 | 17/6/2026 | Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1, when the Saxon XSLT parser is used, allows remote attackers to execute arbitrary code via a crafted XSLT document, related to a "resource injection" issue. | |
| Modificada | Media (5) | 22% | 💥 Exploit | Ektron Content Management System | 14/2/2015 | 17/6/2026 | The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before 8.7sp2 and 9.0 before sp1 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference within an XML document named in the xslt… | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Globiz Solutions Snowfox Content Management System | 8/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators for requests that add a new admin account via a submit action in the admin/accounts/create uri to snowfox/. |