Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.72% | — | Jizhicms | 17/4/2024 | 9/7/2026 | jizhiCMS 2.5 suffers from a File upload vulnerability. | |
| Analizada | Media (6.1) | 0.58% | — | Xunruicms | 16/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbitrary code via the Security.php file in the catalog \XunRuiCMS\dayrui\Fcms\Library. | |
| Analizada | Media (6.5) | 0.67% | — | Wuzhicms | 3/4/2024 | 17/6/2026 | An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file. | |
| Analizada | Alta (8.8) | 1.0% | — | Zhicms | 21/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (8.8) | 0.81% | — | Zhicms | 21/3/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ZhiCms 4.0. This issue affects the function getindexdata of the file app/index/controller/mcontroller.php. The manipulation of the argument key leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.1) | 0.31% | — | Xunruicms | 7/3/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Column Name parameter. | |
| Modificada | Media (6.1) | 0.50% | — | Xunruicms | 2/2/2024 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login. | |
| Modificada | Crítica (9.8) | 0.86% | — | Zhicms | 16/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.64% | — | Wuzhicms | 10/1/2024 | 17/6/2026 | Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the $keywords parameter at /core/admin/copyfrom.php. | |
| Modificada | Crítica (9.8) | 0.61% | — | Jizhicms | 4/1/2024 | 17/6/2026 | Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php. | |
| Modificada | Alta (8.8) | 0.94% | — | Jizhicms | 28/12/2023 | 17/6/2026 | File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory. | |
| Modificada | Alta (7.2) | 2.0% | — | Popojicms | 14/12/2023 | 17/6/2026 | PopojiCMS version 2.0.1 is vulnerable to remote command execution in the Meta Social field. | |
| Modificada | Media (6.1) | 0.44% | — | Xunruicms | 11/12/2023 | 17/6/2026 | XunRuiCMS v4.5.5 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin.php. | |
| Modificada | Media (6.1) | 0.43% | — | Popojicms | 2/11/2023 | 17/6/2026 | A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing of the file install.php of the component Web Config. The manipulation of the argument Site Title with the input <script>alert(1)</script> leads to cross site scripting. The attack may be initiated… | |
| Modificada | Crítica (9.8) | 1.2% | — | Wuzhicms | 1/11/2023 | 17/6/2026 | SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component. | |
| Modificada | Media (5.4) | 0.39% | — | 1234n Minicms | 31/10/2023 | 17/6/2026 | Stored Cross Site Scripting (XSS) vulnerability in MiniCMS 1.1.1 allows attackers to run arbitrary code via crafted string appended to /mc-admin/conf.php. | |
| Modificada | Media (6.5) | 0.73% | — | Jizhicms | 2/10/2023 | 17/6/2026 | There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information | |
| Modificada | Crítica (9.8) | 1.6% | — | Xunruicms | 27/9/2023 | 17/6/2026 | xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request. | |
| Modificada | Crítica (9.8) | 0.86% | — | Icmsdev Icms | 20/9/2023 | 17/6/2026 | Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. | |
| Modificada | Alta (8.8) | 0.41% | — | Icmsdev Icms | 20/9/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files. | |
| Modificada | Alta (7.2) | 0.90% | — | Instantcms Icms2 | 13/9/2023 | 17/6/2026 | SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. | |
| Modificada | Alta (8.8) | 0.27% | — | Idreamsoft Icms | 8/9/2023 | 17/6/2026 | icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Alta (8.8) | 1.0% | — | Wuzhicms | 11/8/2023 | 17/6/2026 | An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php. | |
| Modificada | Crítica (9.8) | 0.61% | — | Idreamsoft Icms | 10/8/2023 | 9/7/2026 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. | |
| Modificada | Crítica (9.8) | 0.61% | — | Idreamsoft Icms | 10/8/2023 | 9/7/2026 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. |