Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.51% | — | Unlcms | 15/9/2018 | 17/6/2026 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay. | |
| Modificada | Media (6.1) | 0.73% | — | Gxlcms | 7/9/2018 | 17/6/2026 | Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php. | |
| Modificada | Media (4.9) | 1.6% | — | Gxlcms | 5/9/2018 | 17/6/2026 | Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator. | |
| Modificada | Alta (7.2) | 1.5% | — | Gxlcms | 5/9/2018 | 17/6/2026 | Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator. | |
| Modificada | Crítica (9.8) | 1.4% | — | Weaselcms Project Weaselcms | 2/9/2018 | 17/6/2026 | There is a PHP code upload vulnerability in WeaselCMS 0.3.6 via index.php because code can be embedded at the end of a .png file when the image/png content type is used. | |
| Modificada | Alta (8.8) | 0.58% | — | Gxlcms | 8/8/2018 | 17/6/2026 | In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account. | |
| Modificada | Alta (8.8) | 0.52% | — | Weaselcms Project Weaselcms | 5/8/2018 | 17/6/2026 | An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI. | |
| Modificada | Alta (8.8) | 0.52% | — | Weaselcms Project Weaselcms | 5/8/2018 | 17/6/2026 | An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php. | |
| Modificada | Media (5.4) | 0.51% | — | Weaselcms Project Weaselcms | 3/8/2018 | 17/6/2026 | An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywords on the SETTINGS page. | |
| Modificada | Crítica (9.8) | 2.1% | — | Gxlcms | 28/7/2018 | 17/6/2026 | The add function in www/Lib/Lib/Action/Admin/TplAction.class.php in Gxlcms v1.1.4 allows remote attackers to read arbitrary files via a crafted index.php?s=Admin-Tpl-ADD-id request, related to Lib/Common/Admin/function.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Gxlcms QY | 8/4/2018 | 17/6/2026 | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Home\HitsAction.class.php allows remote attackers to read data from a database by embedding a FROM clause in a query string within a Home-Hits request, as demonstrated hy sid=user,password%20from%20mysql.user%23. | |
| Modificada | Alta (7.5) | 1.8% | — | Gxlcms QY | 8/4/2018 | 17/6/2026 | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to read any file via a modified pathname in an Admin-Tpl request, as demonstrated by use of '|' instead of '/' as a directory separator, in conjunction with a ".." sequence. | |
| Modificada | Alta (7.5) | 1.8% | — | Gxlcms QY | 8/4/2018 | 17/6/2026 | In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request. | |
| Modificada | Crítica (9.8) | 2.2% | — | Gxlcms QY | 7/4/2018 | 17/6/2026 | In Gxlcms QY v1.0.0713, the upload function in Lib\Lib\Action\Admin\UploadAction.class.php allows remote attackers to execute arbitrary PHP code by first using an Admin-Admin-Configsave request to change the config[upload_class] value from jpg,gif,png,jpeg to jpg,gif,png,jpeg,php and then making an Admin-Upload-Upload… | |
| Modificada | Crítica (9.8) | 1.5% | — | Gxlcms QY | 7/4/2018 | 17/6/2026 | In Gxlcms QY v1.0.0713, the update function in Lib\Lib\Action\Admin\TplAction.class.php allows remote attackers to execute arbitrary PHP code by placing this code into a template. | |
| Modificada | Crítica (9.8) | 1.5% | — | Gxlcms QY | 4/4/2018 | 17/6/2026 | The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary PHP code by placing it after a <?php substring, and then using INTO OUTFILE with a .php filename. | |
| Modificada | Alta (7.5) | 1.5% | — | Gxlcms | 3/10/2017 | 17/6/2026 | Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modified pathnames in the s parameter to index.php, related to Lib/Admin/Action/TplAction.class.php and Lib/Admin/Common/function.php. | |
| Modificada | Media (5.3) | 0.92% | — | IBM Kenexa Lcms Premier | 27/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM Reference #: 1998874. | |
| Modificada | Media (6.5) | 1.2% | — | IBM Kenexa Lcms Premier | 27/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attacker could exploit this vulnerability to capture the cookie and… | |
| Modificada | Alta (7.1) | 0.85% | — | IBM Kenexa Lcms Premier | 1/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1976805. | |
| Modificada | Alta (7.1) | 0.85% | — | IBM Kenexa Lcms Premier | 1/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067. | |
| Modificada | Alta (7.1) | 0.85% | — | IBM Kenexa Lcms Premier | 1/3/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Reference #: 1992067. | |
| Modificada | Alta (8.8) | 1.4% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. | |
| Modificada | Media (5.4) | 0.54% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.5) | 0.99% | — | IBM Kenexa Lcms Premier | 1/2/2017 | 17/6/2026 | IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user. |