Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.29%—Yzmcms17/5/202417/6/2026
A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.
AnalizadaMedia (6.5)0.57%—Sem-cms Semcms7/5/202417/6/2026
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier…
AnalizadaAlta (7.1)0.35%—Yzmcms6/5/202417/6/2026
Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.
ModificadaAlta (7.1)0.47%—Sem-cms Semcms19/4/20249/7/2026
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
AnalizadaCrítica (9.8)0.76%—Sem-cms Semcms19/4/202417/6/2026
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.
AnalizadaCrítica (9.8)1.2%—Sem-cms Semcms3/4/202417/6/2026
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.
AnalizadaAlta (7.5)0.79%—Sem-cms Semcms3/4/202417/6/2026
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.
AnalizadaMedia (6.5)0.74%—Sem-cms Semcms3/4/202417/6/2026
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.
AnalizadaAlta (7.2)0.80%—Sem-cms Semcms29/3/202417/6/2026
SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges.
ModificadaCrítica (9.8)1.0%💥 PoCSem-cms Semcms28/2/202417/6/2026
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.
ModificadaMedia (6.1)0.39%—Yzmcms6/2/202417/6/2026
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
ModificadaAlta (8.8)18%—Mingsoft Mcms5/2/202417/6/2026
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
ModificadaAlta (7.5)1.1%—Mingsoft Mcms16/1/202417/6/2026
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.
ModificadaMedia (6.1)0.36%—Yzmcms11/1/202417/6/2026
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
ModificadaAlta (7.5)0.61%—Sem-cms Semcms10/1/202417/6/2026
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
ModificadaCrítica (9.8)2.2%💥 ExploitMingsoft Mcms30/12/202317/6/2026
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
ModificadaCrítica (9.8)0.63%—Sem-cms Semcms14/12/202317/6/2026
Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.
ModificadaAlta (7.5)0.86%—Sem-cms Semcms4/12/202317/6/2026
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter.…
ModificadaAlta (8.8)0.53%—Yzmcms11/8/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.
ModificadaAlta (7.2)1.1%—Sem-cms Semcms5/8/202317/6/2026
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
ModificadaCrítica (9.8)0.62%—Sem-cms Semcms31/7/20239/7/2026
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
ModificadaMedia (6.1)1.4%💥 ExploitMingsoft Mcms28/7/202317/6/2026
A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…
ModificadaCrítica (9.8)0.89%—Sem-cms Semcms30/6/202317/6/2026
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
ModificadaMedia (6.5)0.46%—Yzmcms20/6/202317/6/2026
Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.
ModificadaCrítica (9.8)0.75%—Sem-cms Semcms19/5/202317/6/2026
SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.
Orbitaley — Vulnerabilidades