Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.42% | — | Eyoucms | 20/1/2023 | 17/6/2026 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_GOBACK_URL". | |
| Modificada | Media (6.1) | 0.42% | — | Eyoucms | 20/1/2023 | 17/6/2026 | EyouCMS <= 1.6.0 was discovered a reflected-XSS in the article publish component in cookie "ENV_LIST_URL". | |
| Modificada | Media (5.4) | 0.54% | — | Eyoucms | 15/12/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic. | |
| Modificada | Media (5.4) | 0.36% | — | Eyoucms | 23/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Alta (7.2) | 3.7% | — | Siyucms | 14/11/2022 | 17/6/2026 | Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a content management system based on ThinkPaP5 AdminLTE. SIYUCMS has a background command execution vulnerability, which can be used by attackers to gain server privileges | |
| Modificada | Media (5.4) | 0.34% | — | Eyoucms | 14/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in EyouCMS V1.5.9-UTF8-SP1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Public Security Record Number text field. | |
| Modificada | Media (6.5) | 0.24% | — | Eyoucms | 14/11/2022 | 17/6/2026 | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information. | |
| Modificada | Alta (8.8) | 0.28% | — | Eyoucms | 14/11/2022 | 17/6/2026 | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module. | |
| Modificada | Alta (8.8) | 0.39% | — | Eyoucms | 14/11/2022 | 17/6/2026 | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module. | |
| Modificada | Alta (8.8) | 0.41% | — | Eyoucms | 18/10/2022 | 17/6/2026 | EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Center, Editorial Membership, and Points Recharge components. | |
| Modificada | Alta (8.8) | 0.87% | — | Ucms Project Ucms | 14/10/2022 | 17/6/2026 | There is a file inclusion vulnerability in the template management module in UCMS 1.6 | |
| Modificada | Media (6.1) | 0.57% | — | Ucms Project Ucms | 19/9/2022 | 17/6/2026 | UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page. | |
| Modificada | Crítica (9.8) | 1.3% | — | Ucms Project Ucms | 12/9/2022 | 17/6/2026 | UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning. | |
| Modificada | Alta (8.8) | 0.47% | — | Eyoucms | 19/8/2022 | 17/6/2026 | EyouCMS V1.5.8-UTF8-SP1 is vulnerable to Cross Site Request Forgery (CSRF) via the background, column management function and add. | |
| Modificada | Media (5.4) | 0.58% | — | Eyoucms | 10/8/2022 | 23/6/2026 | An issue was discovered in EyouCMS 1.5.8. There is a Storage XSS vulnerability that can allows an attacker to execute arbitrary Web scripts or HTML by injecting a special payload via the title parameter in the foreground contribution, allowing the attacker to obtain sensitive information. | |
| Modificada | Crítica (9.8) | 1.1% | — | Ucms Project Ucms | 10/8/2022 | 17/6/2026 | UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. | |
| Modificada | Media (4.8) | 0.49% | — | Eyoucms | 24/6/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in eyoucms v1.5.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL field under the login page. | |
| Modificada | Alta (7.5) | 1.5% | — | Ucms Project Ucms | 21/4/2022 | 17/6/2026 | UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. | |
| Modificada | Crítica (9.1) | 0.99% | — | Ucms Project Ucms | 21/4/2022 | 17/6/2026 | UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. | |
| Modificada | Alta (8.8) | 1.7% | — | Ucms Project Ucms | 21/4/2022 | 17/6/2026 | An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (6.1) | 0.72% | — | Cxuucms | 29/3/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Eyoucms | 28/3/2022 | 17/6/2026 | EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities. | |
| Modificada | Crítica (9.8) | 1.8% | — | Eyoucms | 24/3/2022 | 17/6/2026 | EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata. | |
| Modificada | Alta (7.2) | 1.1% | — | Eyoucms | 20/3/2022 | 17/6/2026 | The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability. | |
| Modificada | Alta (8.1) | 1.1% | — | Eyoucms | 14/1/2022 | 17/6/2026 | eyouCMS V1.5.5-UTF8-SP3_1 suffers from Arbitrary file deletion due to insufficient filtering of the parameter filename. |