Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.29% | — | Yzmcms | 17/5/2024 | 17/6/2026 | A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker. | |
| Analizada | Media (6.5) | 0.57% | — | Sem-cms Semcms | 7/5/2024 | 17/6/2026 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Analizada | Alta (7.1) | 0.35% | — | Yzmcms | 6/5/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings. | |
| Modificada | Alta (7.1) | 0.47% | — | Sem-cms Semcms | 19/4/2024 | 9/7/2026 | An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. | |
| Analizada | Crítica (9.8) | 0.76% | — | Sem-cms Semcms | 19/4/2024 | 17/6/2026 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component. | |
| Analizada | Crítica (9.8) | 1.2% | — | Sem-cms Semcms | 3/4/2024 | 17/6/2026 | An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file. | |
| Analizada | Alta (7.5) | 0.79% | — | Sem-cms Semcms | 3/4/2024 | 17/6/2026 | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php. | |
| Analizada | Media (6.5) | 0.74% | — | Sem-cms Semcms | 3/4/2024 | 17/6/2026 | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php. | |
| Analizada | Alta (7.2) | 0.80% | — | Sem-cms Semcms | 29/3/2024 | 17/6/2026 | SEMCMS 4.8 is vulnerable to Incorrect Access Control. The code installs SEMCMS_Funtion.php before checking if the admin is a valid user in the admin page because authentication function is called from there, users gain admin privileges. | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Sem-cms Semcms | 28/2/2024 | 17/6/2026 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component. | |
| Modificada | Media (6.1) | 0.39% | — | Yzmcms | 6/2/2024 | 17/6/2026 | An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL. | |
| Modificada | Alta (8.8) | 18% | — | Mingsoft Mcms | 5/2/2024 | 17/6/2026 | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do. | |
| Modificada | Alta (7.5) | 1.1% | — | Mingsoft Mcms | 16/1/2024 | 17/6/2026 | An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter. | |
| Modificada | Media (6.1) | 0.36% | — | Yzmcms | 11/1/2024 | 17/6/2026 | member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header. | |
| Modificada | Alta (7.5) | 0.61% | — | Sem-cms Semcms | 10/1/2024 | 17/6/2026 | SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Mingsoft Mcms | 30/12/2023 | 17/6/2026 | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do. | |
| Modificada | Crítica (9.8) | 0.63% | — | Sem-cms Semcms | 14/12/2023 | 17/6/2026 | Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php. | |
| Modificada | Alta (7.5) | 0.86% | — | Sem-cms Semcms | 4/12/2023 | 17/6/2026 | SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter.… | |
| Modificada | Alta (8.8) | 0.53% | — | Yzmcms | 11/8/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint. | |
| Modificada | Alta (7.2) | 1.1% | — | Sem-cms Semcms | 5/8/2023 | 17/6/2026 | File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php. | |
| Modificada | Crítica (9.8) | 0.62% | — | Sem-cms Semcms | 31/7/2023 | 9/7/2026 | SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Mingsoft Mcms | 28/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.89% | — | Sem-cms Semcms | 30/6/2023 | 17/6/2026 | File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges. | |
| Modificada | Media (6.5) | 0.46% | — | Yzmcms | 20/6/2023 | 17/6/2026 | Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function. | |
| Modificada | Crítica (9.8) | 0.75% | — | Sem-cms Semcms | 19/5/2023 | 17/6/2026 | SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php. |