Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.19% | — | Idccms | 22/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN. | |
| Analizada | Alta (8.3) | 0.22% | — | Idccms | 22/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close. | |
| Analizada | Alta (8.8) | 0.29% | — | Idccms | 22/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN. | |
| Analizada | Media (4.3) | 0.21% | — | Idccms | 22/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add. | |
| Analizada | Media (6.3) | 0.20% | — | Idccms | 22/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev. | |
| Analizada | Baja (3.8) | 0.19% | — | Idccms | 16/5/2024 | 17/6/2026 | idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area. | |
| Analizada | Media (6.5) | 0.38% | 💥 PoC | Idccms | 16/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add | |
| Analizada | Media (5.4) | 0.19% | — | Idccms | 16/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet. | |
| Analizada | Media (6.5) | 0.19% | — | Idccms | 15/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&nohrefStr=close. | |
| Analizada | Alta (8.8) | 0.33% | — | Idccms | 15/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&dataType=&dataTypeCN. | |
| Analizada | Media (6.3) | 0.23% | — | Idccms | 14/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&nohrefStr=close. | |
| Analizada | Media (5.4) | 0.19% | — | Idccms | 14/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&nohrefStr=close. | |
| Analizada | Alta (8.8) | 0.30% | — | Idccms | 14/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&dataType=&dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&theme=cs&dataID=6. | |
| Analizada | Alta (8.8) | 0.30% | — | Idccms | 14/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=&fieldName=state&fieldName2=state&tabName=banner&dataID=6. | |
| Analizada | Alta (8.1) | 0.30% | — | Idccms | 6/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache. | |
| Analizada | Media (5.4) | 0.21% | — | Idccms | 6/5/2024 | 17/6/2026 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache. | |
| Analizada | Media (4.3) | 0.43% | — | Idccms | 25/4/2024 | 17/6/2026 | A vulnerability classified as problematic was found in idcCMS 1.35. Affected by this vulnerability is an unknown functionality of the file /admin/admin_cl.php?mudi=revPwd. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Alta (7.3) | 0.92% | — | Maccms | 19/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload. | |
| Analizada | Alta (8.8) | 0.88% | — | Publiccms | 16/4/2024 | 17/6/2026 | An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function. | |
| Analizada | Media (6.9) | 0.32% | — | Publiccms | 26/3/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted… | |
| Modificada | Media (5.4) | 0.30% | — | Publiccms | 10/1/2024 | 17/6/2026 | PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing. | |
| Modificada | Crítica (9.8) | 1.5% | — | Publiccms | 20/11/2023 | 17/6/2026 | Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function. | |
| Modificada | Media (6.5) | 0.65% | — | Publiccms | 16/11/2023 | 17/6/2026 | An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component. | |
| Modificada | Alta (8.8) | 0.64% | — | Chshcms Mccms | 17/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of… | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Publiccms | 15/6/2023 | 17/6/2026 | PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions. |