Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

192 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.72%—Bloofoxcms13/4/202317/6/2026
bloofox v0.5.2 was discovered to contain a SQL injection vulnerability via the component /index.php?mode=content&page=pages&action=edit&eid=1.
ModificadaCrítica (9.1)1.2%—Bloofoxcms13/4/20239/7/2026
bloofox v0.5.2 was discovered to contain an arbitrary file deletion vulnerability via the delete_file() function.
ModificadaCrítica (9.8)0.49%—Lmxcms10/3/202317/6/2026
A vulnerability was found in lmxcms 1.41 and classified as critical. Affected by this issue is the function reply of the file BookAction.class.php. The manipulation of the argument id with the input 1) and updatexml(0,concat(0x7e,user()),1)# leads to sql injection. The attack may be launched remotely. The exploit has…
ModificadaCrítica (9.8)0.49%—Lmxcms10/3/202317/6/2026
A vulnerability has been found in lmxcms 1.41 and classified as critical. Affected by this vulnerability is the function update of the file AcquisiAction.class.php. The manipulation of the argument id with the input -1 and updatexml(0,concat(0x7e,user()),1)# leads to sql injection. The attack can be launched remotely.…
ModificadaMedia (6.5)0.82%—Lmxcms1/2/202317/6/2026
lmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php.
ModificadaMedia (4.9)0.67%—Lmxcms1/2/202317/6/2026
lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php.
ModificadaMedia (6.5)1.0%—Bloofoxcms26/1/202317/6/2026
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file deletion vulnerability via the component /include/inc_content_media.php.
ModificadaAlta (8)0.47%—Duxcms Project Duxcms8/12/202217/6/2026
A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability…
ModificadaMedia (5.4)0.40%—Duxcms Project Duxcms8/12/202217/6/2026
A vulnerability was found in annyshow DuxCMS 2.1. It has been classified as problematic. This affects an unknown part of the file admin.php&r=article/AdminContent/edit of the component Article Handler. The manipulation of the argument content leads to cross site scripting. It is possible to initiate the attack…
ModificadaAlta (7.2)0.98%—Gxcms Project Gxcms17/5/202217/6/2026
GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content and then rename to PHP suffix file, after calling PHP file can control the server.
ModificadaMedia (6.5)1.1%—Ujcms Jspxcms4/5/202217/6/2026
Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.
ModificadaAlta (8.8)1.3%—Bloofoxcms26/4/202217/6/2026
bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.
ModificadaMedia (5.4)0.88%—Metalgenix Genixcms3/3/202217/6/2026
In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters.
ModificadaCrítica (9.8)1.4%—Bloofoxcms24/2/202217/6/2026
Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.
ModificadaMedia (5.4)0.49%—Bloofoxcms24/2/202217/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and (2) type parameter in an edit action in index.php.
ModificadaCrítica (9.8)1.2%—Duxcms Project Duxcms16/2/202217/6/2026
DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.
ModificadaCrítica (9.8)14%—Ujcms Jspxcms4/2/202217/6/2026
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.
ModificadaBaja (2.7)0.97%—Bloofoxcms16/6/202117/6/2026
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
ModificadaMedia (5.4)0.83%—Bloofoxcms16/6/202117/6/2026
bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
ModificadaCrítica (9.8)1.9%—Bloofoxcms16/6/202117/6/2026
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
ModificadaMedia (6.5)0.84%—Bloofoxcms16/6/202117/6/2026
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
ModificadaMedia (6.5)1.4%—Bloofoxcms4/6/202117/6/2026
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
ModificadaAlta (8.8)1.3%—Bloofoxcms4/6/202117/6/2026
BloofoxCMS 0.5.2.1 allows Unrestricted File Upload vulnerability via bypass MIME Type validation by inserting 'image/jpeg' within the 'Content-Type' header.
ModificadaMedia (6.5)0.57%—Bloofoxcms4/6/202117/6/2026
BloofoxCMS 0.5.2.1 allows Cross-Site Request Forgery (CSRF) via 'mode=settings&page=editor', as demonstrated by use of 'mode=settings&page=editor' to change any file content (Locally/Remotely).
ModificadaMedia (5.4)0.52%—Bloofoxcms4/6/202117/6/2026
BloofoxCMS 0.5.2.1 allows Reflected Cross-Site Scripting (XSS) vulnerability by inserting a XSS payload within the 'fileurl' parameter.
Orbitaley — Vulnerabilidades