Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.53% | — | Cszcms CSZ CMS | 22/8/2023 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter. | |
| Modificada | Media (5.4) | 0.50% | — | Cszcms CSZ CMS | 18/8/2023 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields. | |
| Modificada | Media (6.1) | 0.50% | — | Cszcms CSZ CMS | 18/8/2023 | 17/6/2026 | CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin. | |
| Modificada | Alta (7.5) | 0.64% | — | Cskaza Cszcms | 11/8/2023 | 17/6/2026 | SQL Injection vulnerability in cskaza cszcms version 1.2.9, allows attackers to gain sensitive information via pm_sendmail parameter in csz_model.php. | |
| Modificada | Crítica (9.8) | 0.82% | — | Cskaza Cszcms | 9/8/2023 | 17/6/2026 | A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL. | |
| Modificada | Alta (8.8) | 0.54% | — | Zzcms | 3/7/2023 | 17/6/2026 | Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.php. | |
| Modificada | Alta (8.8) | 0.80% | — | Cszcms CSZ CMS | 23/3/2023 | 17/6/2026 | File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file. | |
| Modificada | Media (5.4) | 0.39% | — | Zzcms | 7/12/2022 | 17/6/2026 | An issue was discovered in ZZCMS 2022. There is a cross-site scripting (XSS) vulnerability in admin/ad_list.php. | |
| Modificada | Alta (7.2) | 0.97% | — | Zzcms | 22/9/2022 | 17/6/2026 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php. | |
| Modificada | Alta (7.2) | 0.85% | — | Zzcms | 22/9/2022 | 17/6/2026 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&groupid=. | |
| Modificada | Media (5.3) | 1.0% | — | Zzcms | 22/9/2022 | 17/6/2026 | ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server. | |
| Modificada | Media (5.3) | 2.7% | — | Zzcms | 22/9/2022 | 17/6/2026 | An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GET request sent to /one/siteinfo.php. | |
| Modificada | Alta (7.2) | 0.94% | — | Zzcms | 17/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter. | |
| Modificada | Alta (8.8) | 0.95% | — | Zzcms | 17/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie. | |
| Modificada | Alta (7.2) | 0.94% | — | Zzcms | 17/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter. | |
| Modificada | Alta (8.8) | 0.98% | — | Zzcms | 17/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter. | |
| Modificada | Alta (8.8) | 0.95% | — | Zzcms | 17/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter. | |
| Modificada | Alta (7.2) | 0.94% | — | Zzcms | 17/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter. | |
| Modificada | Alta (7.2) | 0.94% | — | Zzcms | 17/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter. | |
| Modificada | Alta (8.8) | 0.95% | — | Zzcms | 17/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie. | |
| Modificada | Crítica (9.8) | 1.4% | — | Zzcms | 2/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma. | |
| Modificada | Crítica (9.8) | 1.4% | — | Zzcms | 2/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma. | |
| Modificada | Crítica (9.8) | 1.4% | — | Zzcms | 2/6/2022 | 17/6/2026 | An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Cszcms | 23/5/2022 | 17/6/2026 | CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/. | |
| Modificada | Media (5.4) | 0.61% | — | Zcms Project Zcms | 26/4/2022 | 17/6/2026 | ZCMS v20170206 was discovered to contain a stored cross-site scripting (XSS) vulnerability via index.php?m=home&c=message&a=add. |