Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 2.2% | — | Globiz Solutions Snowfox Content Management System | 8/12/2014 | 17/6/2026 | Open redirect vulnerability in modules/system/controller/selectlanguage.class.php in Snowfox CMS 1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the rd parameter in a submit action to snowfox/. | |
| Modificada | Media (5) | 1.2% | — | Ddsn CM3 Acora Content Management System | 6/6/2014 | 16/6/2026 | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a .. (dot dot) in the "l" parameter, which reveals the installation path in an error message. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Ddsn CM3 Acora Content Management System | 6/6/2014 | 16/6/2026 | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx. | |
| Modificada | Media (5) | 1.2% | — | Ddsn CM3 Acora Content Management System | 6/6/2014 | 16/6/2026 | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the secure flag for an unspecified cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | |
| Modificada | Media (5) | 1.2% | — | Ddsn CM3 Acora Content Management System | 6/6/2014 | 16/6/2026 | DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Media (6.8) | 1.1% | — | Ddsn CM3 Acora Content Management System | 25/4/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (5.8) | 2.0% | — | Ddsn CM3 Acora Content Management System | 25/4/2014 | 16/6/2026 | Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the l parameter to track.aspx. | |
| Modificada | Media (4.3) | 1.9% | — | Ddsn CM3 Acora Content Management System | 25/4/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) url, (3) qstr parameter. | |
| Modificada | Baja (3.5) | 0.97% | — | Ektron Content Management System | 25/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in content.aspx in Ektron CMS 8.7 before 8.7.0.055 allows remote authenticated users to inject arbitrary web script or HTML via the category0 parameter, which is not properly handled when displaying the Subjects tab in the View Properties menu option. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Cynthia Fridsma Horizon Quick Content Management System | 9/1/2014 | 17/6/2026 | SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter. | |
| Modificada | Media (5) | 1.9% | — | Horizon Quick Content Management System Project Horizon Quick Content Management System | 9/1/2014 | 17/6/2026 | Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Cms-center Simple WEB Content Management System | 21/6/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) item_delete.php, (2) item_status.php, (3) item_detail.php, (4) item_modify.php, or (5) item_position.php in admin/; or (6) status parameter to… | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Pangramsoft Pointter PHP Content Management System | 22/12/2010 | 16/6/2026 | Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies. | |
| Modificada | Media (6.8) | 1.3% | — | IBM Websphere PortalIBM Lotus WEB Content ManagementIBM Lotus Workplace WEB Content ManagementIBM Lotus Quickr | 26/2/2010 | 16/6/2026 | Open redirect vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0, 8.0.0.2, 8.1,… | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | IBM Websphere PortalIBM Lotus WEB Content ManagementIBM Lotus Workplace WEB Content ManagementIBM Lotus Quickr | 26/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.jsp in IBM WebSphere Portal, IBM Lotus Web Content Management (WCM), and IBM Lotus Workplace Web Content Management 5.1.0.0 through 5.1.0.5, 6.0.0.0 through 6.0.0.4, 6.0.1.0 through 6.0.1.7, 6.1.0.0 through 6.1.0.3, and 6.1.5.0; and IBM Lotus Quickr services 8.0,… | |
| Modificada | Media (4.3) | 1.5% | — | IBM Lotus WEB Content Management | 20/1/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Phpfaber Content Management System | 22/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in module.php in PHPFABER CMS, possibly 1.3.36, allows remote attackers to inject arbitrary web script or HTML via the mod parameter. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Tgs-cms TGS Content Management | 21/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL commands via the (1) tgs_language_id, (2) tpl_dir, (3) referer, (4) user-agent, (5) site, (6) option, (7) db_optimization, (8) owner, (9) admin_email, (10) default_language, and (11) db_host parameters… | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Tgs-cms TGS Content Management | 21/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject arbitrary web script or HTML via the previous_page parameter, a different vector than CVE-2008-6839. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Tgs-cms TGS Content Management | 27/6/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TGS Content Management 0.3.2r2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg and (2) goodmsg parameters to (a) login.php and (b) index.php, and the (3) dir and (4) id parameters to index.php. NOTE: the provenance of this information… | |
| Modificada | Media (5) | 2.2% | 💥 Exploit | Easy-news Easy Content Management Publishing | 20/3/2009 | 16/6/2026 | Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database/News.mdb. | |
| Modificada | Alta (7.5) | 1.4% | — | Vignette Content Management | 6/3/2009 | 16/6/2026 | Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator privileges via unknown attack vectors. | |
| Modificada | Media (6.8) | 0.56% | — | IBM Workplace FOR Business Controls AND ReportingIBM Workplace WEB Content Management | 10/2/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x has unknown impact and remote attack vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Workplace FOR Business Controls AND ReportingIBM Workplace WEB Content Management | 10/2/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Workplace for Business Controls and Reporting 2.x and IBM Workplace Web Content Management 6.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information. | |
| Modificada | Baja (2.6) | 1.2% | — | IBM Workplace Content Management | 25/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Workplace Content Management (WCM) 6.0G and 6.1 before CF8, when a Page Navigation Component shows menu entries, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in the URI, related to parameters "not being encoded." |