Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.38% | — | Eyoucms | 22/6/2023 | 17/6/2026 | There is a storage type cross site scripting (XSS) vulnerability in the filing number of the Basic Information tab on the backend management page of EyouCMS v1.6.3 | |
| Modificada | Media (4.8) | 0.35% | — | Eyoucms | 19/6/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Eyoucms v1.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the web_recordnum parameter. | |
| Modificada | Media (5.4) | 0.34% | — | Eyoucms | 12/6/2023 | 17/6/2026 | EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (5.4) | 0.56% | — | Gougucms Pythagorean OA Office System | 1/6/2023 | 17/6/2026 | A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Schedule Handler. The manipulation of the argument description leads to cross site scripting. The attack can be launched… | |
| Modificada | Media (4.3) | 0.26% | — | Eyoucms | 23/5/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) in EyouCMS v1.6.2 allows attackers to execute arbitrary commands via a supplying a crafted HTML file to the Upload software format function. | |
| Modificada | Media (5.4) | 0.60% | — | Sucms Project Sucms | 17/5/2023 | 17/6/2026 | A vulnerability was found in Sucms 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin_ads.php?action=add. The manipulation of the argument intro leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.1) | 0.42% | — | Eyoucms | 28/4/2023 | 17/6/2026 | EyouCms V1.6.1-UTF8-sp1 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (6.1) | 0.55% | — | Ucms Project Ucms | 26/4/2023 | 17/6/2026 | A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file saddpost.php of the component Column Configuration. The manipulation of the argument strorder leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.61% | — | Eyoucms | 14/4/2023 | 17/6/2026 | A vulnerability was found in EyouCms up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /yxcms/index.php?r=admin/extendfield/mesedit&tabid=12&id=4 of the component HTTP POST Request Handler. The manipulation of the argument web_ico leads to cross… | |
| Modificada | Media (6.1) | 0.62% | — | Eyoucms | 14/4/2023 | 17/6/2026 | A vulnerability was found in EyouCms 1.5.4. It has been classified as problematic. Affected is an unknown function of the file login.php?m=admin&c=Arctype&a=edit of the component New Picture Handler. The manipulation of the argument litpic_loca leads to cross site scripting. It is possible to launch the attack… | |
| Modificada | Media (5.4) | 0.59% | — | Eyoucms | 2/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in EyouCMS up to 1.5.4. This affects an unknown part of the file login.php. The manipulation of the argument tag_tag leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (5.4) | 0.60% | — | Eyoucms | 2/4/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in EyouCMS up to 1.5.4. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument typename leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.1) | 0.61% | — | Muyucms | 28/3/2023 | 17/6/2026 | MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /database/sqldel.html. | |
| Modificada | Alta (8.1) | 0.81% | — | Muyucms Project Muyucms | 28/3/2023 | 17/6/2026 | MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /accessory/picdel.html. | |
| Modificada | Crítica (9.8) | 0.79% | — | Ucms Project Ucms | 9/3/2023 | 17/6/2026 | A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadmin/fileedit.php of the component System File Management Module. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The associated… | |
| Modificada | Alta (8.8) | 0.60% | — | Muyucms | 26/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in MuYuCMS 2.2. This affects an unknown part of the file /admin.php/update/getFile.html. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (8.1) | 0.94% | — | Muyucms | 26/2/2023 | 17/6/2026 | A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin.php/accessory/filesdel.html. The manipulation of the argument filedelur leads to relative path traversal. The attack may be launched remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 1.1% | — | Muyucms | 26/2/2023 | 17/6/2026 | A vulnerability was found in MuYuCMS 2.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /editor/index.php. The manipulation of the argument file_path leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Media (4.3) | 0.74% | — | Muyucms | 26/2/2023 | 17/6/2026 | A vulnerability was found in MuYuCMS 2.2. It has been classified as problematic. Affected is an unknown function of the file /editor/index.php. The manipulation of the argument dir_path leads to relative path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Media (6.5) | 1.0% | — | Muyucms | 24/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in MuYuCMS 2.2. This issue affects some unknown processing of the file index.php. The manipulation of the argument file_path leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (5.4) | 0.45% | — | Eyoucms | 8/2/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page description on the basic information page. | |
| Modificada | Media (5.4) | 0.38% | — | Eyoucms | 20/1/2023 | 17/6/2026 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the FileManager component in GET parameter "filename" when editing any file. | |
| Modificada | Media (6.1) | 0.42% | — | Eyoucms | 20/1/2023 | 17/6/2026 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article attribute editor component in POST value "value" if the value contains a non-integer char. | |
| Modificada | Media (6.1) | 0.42% | — | Eyoucms | 20/1/2023 | 17/6/2026 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in article type editor component in POST value "name" if the value contains a malformed UTF-8 char. | |
| Modificada | Media (6.1) | 0.42% | — | Eyoucms | 20/1/2023 | 17/6/2026 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in FileManager component in GET value "activepath" when creating a new file. |