Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.92%—Mingsoft Mcms8/5/202317/6/2026
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
ModificadaCrítica (9.8)0.78%—Sem-cms Semcms5/5/202317/6/2026
Semcms Shop v4.2 was discovered to contain an arbitrary file uplaod vulnerability via the component SEMCMS_Upfile.php. This vulnerability allows attackers to execute arbitrary code via uploading a crafted PHP file.
ModificadaCrítica (9.8)1.4%—Mingsoft Mcms4/4/202317/6/2026
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.
ModificadaMedia (5.4)0.45%—Yzmcms3/2/20239/7/2026
Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function.
ModificadaAlta (8.8)1.0%—Mingsoft Mcms26/1/202317/6/2026
MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.
ModificadaMedia (5.4)0.42%—Mingsoft Mcms21/12/202217/6/2026
A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.…
ModificadaCrítica (9.8)3.0%💥 ExploitMingsoft Mcms9/12/202217/6/2026
A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
ModificadaMedia (6.1)0.41%—Mingsoft Mcms8/12/202217/6/2026
A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may…
ModificadaCrítica (9.8)0.68%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php.
ModificadaCrítica (9.8)0.81%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php.
ModificadaCrítica (9.8)0.68%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php.
ModificadaCrítica (9.8)0.85%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php.
ModificadaCrítica (9.8)0.85%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php.
ModificadaMedia (6.1)0.48%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS SHOP v 1.1 is vulnerable to Cross Site Scripting (XSS) via Ant_M_Coup.php.
ModificadaCrítica (9.8)0.80%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS v 1.2 is vulnerable to SQL Injection via SEMCMS_User.php.
ModificadaCrítica (9.8)0.85%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS v 1.1 is vulnerable to SQL Injection via Ant_Pro.php.
ModificadaCrítica (9.8)0.85%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS Shop V 1.1 is vulnerable to SQL Injection via Ant_Global.php.
ModificadaCrítica (9.8)0.85%—Sem-cms Semcms28/10/202217/6/2026
SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php.
ModificadaCrítica (9.8)1.1%—Mingsoft Mcms16/8/202217/6/2026
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
ModificadaCrítica (9.8)1.1%—Mingsoft Mcms16/8/202217/6/2026
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.
ModificadaCrítica (9.8)0.73%—Sem-cms Semcms9/8/202217/6/2026
A vulnerability classified as critical has been found in SEMCMS. This affects an unknown part of the file Ant_Check.php. The manipulation of the argument DID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier…
ModificadaCrítica (9.8)1.5%—Mingsoft Mcms1/7/202217/6/2026
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
ModificadaCrítica (9.8)2.6%—Mingsoft Mcms2/6/202217/6/2026
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.
ModificadaAlta (8.8)0.65%—Mingsoft Mcms2/6/202217/6/2026
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
ModificadaCrítica (9.8)1.5%—Mingsoft Mcms11/5/202217/6/2026
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
Orbitaley — Vulnerabilidades