Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.72% | — | Bloofoxcms | 13/4/2023 | 17/6/2026 | bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1. | |
| Modificada | Crítica (9.1) | 1.2% | — | Bloofoxcms | 13/4/2023 | 9/7/2026 | bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function. | |
| Modificada | Crítica (9.8) | 0.49% | — | Lmxcms | 10/3/2023 | 17/6/2026 | A vulnerability was found in lmxcms 1.41 and classified as critical. Affected by this issue is the function reply of the file BookAction.class.php. The manipulation of the argument id with the input 1) and updatexml(0,concat(0x7e,user()),1)# leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.49% | — | Lmxcms | 10/3/2023 | 17/6/2026 | A vulnerability has been found in lmxcms 1.41 and classified as critical. Affected by this vulnerability is the function update of the file AcquisiAction.class.php. The manipulation of the argument id with the input -1 and updatexml(0,concat(0x7e,user()),1)# leads to sql injection. The attack can be launched remotely.… | |
| Modificada | Media (6.5) | 0.82% | — | Lmxcms | 1/2/2023 | 17/6/2026 | lmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php. | |
| Modificada | Media (4.9) | 0.67% | — | Lmxcms | 1/2/2023 | 17/6/2026 | lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php. | |
| Modificada | Media (6.5) | 1.0% | — | Bloofoxcms | 26/1/2023 | 17/6/2026 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php. | |
| Modificada | Alta (8) | 0.47% | — | Duxcms Project Duxcms | 8/12/2022 | 17/6/2026 | A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability… | |
| Modificada | Media (5.4) | 0.40% | — | Duxcms Project Duxcms | 8/12/2022 | 17/6/2026 | A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of the file admin.php&r=article/AdminContent/edit of the component Article Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack… | |
| Modificada | Alta (7.2) | 0.98% | — | Gxcms Project Gxcms | 17/5/2022 | 17/6/2026 | GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content and then rename to PHP suffix file, after calling PHP file can control the server. | |
| Modificada | Media (6.5) | 1.1% | — | Ujcms Jspxcms | 4/5/2022 | 17/6/2026 | Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=. | |
| Modificada | Alta (8.8) | 1.3% | — | Bloofoxcms | 26/4/2022 | 17/6/2026 | bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit. | |
| Modificada | Media (5.4) | 0.88% | — | Metalgenix Genixcms | 3/3/2022 | 17/6/2026 | In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters. | |
| Modificada | Crítica (9.8) | 1.4% | — | Bloofoxcms | 24/2/2022 | 17/6/2026 | Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php. | |
| Modificada | Media (5.4) | 0.49% | — | Bloofoxcms | 24/2/2022 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Duxcms Project Duxcms | 16/2/2022 | 17/6/2026 | DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=. | |
| Modificada | Crítica (9.8) | 14% | — | Ujcms Jspxcms | 4/2/2022 | 17/6/2026 | A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files. | |
| Modificada | Baja (2.7) | 0.97% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files. | |
| Modificada | Media (5.4) | 0.83% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code. | |
| Modificada | Crítica (9.8) | 1.9% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files). | |
| Modificada | Media (6.5) | 0.84% | — | Bloofoxcms | 16/6/2021 | 17/6/2026 | bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely). | |
| Modificada | Media (6.5) | 1.4% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. | |
| Modificada | Alta (8.8) | 1.3% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header. | |
| Modificada | Media (6.5) | 0.57% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely). | |
| Modificada | Media (5.4) | 0.52% | — | Bloofoxcms | 4/6/2021 | 17/6/2026 | BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter. |