Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.72%—Jizhicms17/4/20249/7/2026
jizhiCMS 2.5 suffers from a File upload vulnerability.
AnalizadaMedia (6.1)0.58%—Xunruicms16/4/202417/6/2026
Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbitrary code via the Security.php file in the catalog \XunRuiCMS\dayrui\Fcms\Library.
AnalizadaMedia (6.5)0.67%—Wuzhicms3/4/202417/6/2026
An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.
AnalizadaAlta (8.8)1.0%—Zhicms21/3/202417/6/2026
A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaAlta (8.8)0.81%—Zhicms21/3/202417/6/2026
A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The manipulation of the argument key leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
ModificadaMedia (6.1)0.31%—Xunruicms7/3/202417/6/2026
A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Column Name parameter.
ModificadaMedia (6.1)0.50%—Xunruicms2/2/202417/6/2026
Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.
ModificadaCrítica (9.8)0.86%—Zhicms16/1/202417/6/2026
A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
ModificadaCrítica (9.8)0.64%—Wuzhicms10/1/202417/6/2026
Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php.
ModificadaCrítica (9.8)0.61%—Jizhicms4/1/202417/6/2026
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.
ModificadaAlta (8.8)0.94%—Jizhicms28/12/202317/6/2026
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
ModificadaAlta (7.2)2.0%—Popojicms14/12/202317/6/2026
PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field.
ModificadaMedia (6.1)0.44%—Xunruicms11/12/202317/6/2026
XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin.php.
ModificadaMedia (6.1)0.43%—Popojicms2/11/202317/6/2026
A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing of the file install.php of the component Web Config. The manipulation of the argument Site Title with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated…
ModificadaCrítica (9.8)1.2%—Wuzhicms1/11/202317/6/2026
SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.
ModificadaMedia (5.4)0.39%—1234n Minicms31/10/202317/6/2026
Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php.
ModificadaMedia (6.5)0.73%—Jizhicms2/10/202317/6/2026
There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
ModificadaCrítica (9.8)1.6%—Xunruicms27/9/202317/6/2026
xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.
ModificadaCrítica (9.8)0.86%—Icmsdev Icms20/9/202317/6/2026
Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.
ModificadaAlta (8.8)0.41%—Icmsdev Icms20/9/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files.
ModificadaAlta (7.2)0.90%—Instantcms Icms213/9/202317/6/2026
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
ModificadaAlta (8.8)0.27%—Idreamsoft Icms8/9/202317/6/2026
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
ModificadaAlta (8.8)1.0%—Wuzhicms11/8/202317/6/2026
An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.
ModificadaCrítica (9.8)0.61%—Idreamsoft Icms10/8/20239/7/2026
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
ModificadaCrítica (9.8)0.61%—Idreamsoft Icms10/8/20239/7/2026
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.