Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.92% | — | Mingsoft Mcms | 8/5/2023 | 17/6/2026 | File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943. | |
| Modificada | Crítica (9.8) | 0.78% | — | Sem-cms Semcms | 5/5/2023 | 17/6/2026 | Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Modificada | Crítica (9.8) | 1.4% | — | Mingsoft Mcms | 4/4/2023 | 17/6/2026 | SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter. | |
| Modificada | Media (5.4) | 0.45% | — | Yzmcms | 3/2/2023 | 9/7/2026 | Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function. | |
| Modificada | Alta (8.8) | 1.0% | — | Mingsoft Mcms | 26/1/2023 | 17/6/2026 | MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do. | |
| Modificada | Media (5.4) | 0.42% | — | Mingsoft Mcms | 21/12/2022 | 17/6/2026 | A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Mingsoft Mcms | 9/12/2022 | 17/6/2026 | A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (6.1) | 0.41% | — | Mingsoft Mcms | 8/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Crítica (9.8) | 0.68% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php. | |
| Modificada | Crítica (9.8) | 0.81% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php. | |
| Modificada | Crítica (9.8) | 0.68% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php. | |
| Modificada | Crítica (9.8) | 0.85% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php. | |
| Modificada | Crítica (9.8) | 0.85% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php. | |
| Modificada | Media (6.1) | 0.48% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php. | |
| Modificada | Crítica (9.8) | 0.80% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php. | |
| Modificada | Crítica (9.8) | 0.85% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php. | |
| Modificada | Crítica (9.8) | 0.85% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php. | |
| Modificada | Crítica (9.8) | 0.85% | — | Sem-cms Semcms | 28/10/2022 | 17/6/2026 | SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mingsoft Mcms | 16/8/2022 | 17/6/2026 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mingsoft Mcms | 16/8/2022 | 17/6/2026 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter. | |
| Modificada | Crítica (9.8) | 0.73% | — | Sem-cms Semcms | 9/8/2022 | 17/6/2026 | A vulnerability classified as critical has been found in SEMCMS. This affects an unknown part of the file Ant_Check.php. The manipulation of the argument DID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier… | |
| Modificada | Crítica (9.8) | 1.5% | — | Mingsoft Mcms | 1/7/2022 | 17/6/2026 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. | |
| Modificada | Crítica (9.8) | 2.6% | — | Mingsoft Mcms | 2/6/2022 | 17/6/2026 | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file. | |
| Modificada | Alta (8.8) | 0.65% | — | Mingsoft Mcms | 2/6/2022 | 17/6/2026 | An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mingsoft Mcms | 11/5/2022 | 17/6/2026 | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter. |