Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.19%—Idccms22/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN.
AnalizadaAlta (8.3)0.22%—Idccms22/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.
AnalizadaAlta (8.8)0.29%—Idccms22/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.
AnalizadaMedia (4.3)0.21%—Idccms22/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add.
AnalizadaMedia (6.3)0.20%—Idccms22/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev.
AnalizadaBaja (3.8)0.19%—Idccms16/5/202417/6/2026
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.
AnalizadaMedia (6.5)0.38%💥 PoCIdccms16/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add
AnalizadaMedia (5.4)0.19%—Idccms16/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.
AnalizadaMedia (6.5)0.19%—Idccms15/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&nohrefStr=close.
AnalizadaAlta (8.8)0.33%—Idccms15/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&dataType=&dataTypeCN.
AnalizadaMedia (6.3)0.23%—Idccms14/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&nohrefStr=close.
AnalizadaMedia (5.4)0.19%—Idccms14/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&nohrefStr=close.
AnalizadaAlta (8.8)0.30%—Idccms14/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&dataType=&dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&theme=cs&dataID=6.
AnalizadaAlta (8.8)0.30%—Idccms14/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=&fieldName=state&fieldName2=state&tabName=banner&dataID=6.
AnalizadaAlta (8.1)0.30%—Idccms6/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.
AnalizadaMedia (5.4)0.21%—Idccms6/5/202417/6/2026
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.
AnalizadaMedia (4.3)0.43%—Idccms25/4/202417/6/2026
A vulnerability classified as problematic was found in idcCMS 1.35. Affected by this vulnerability is an unknown functionality of the file /admin/admin_cl.php?mudi=revPwd. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be…
AnalizadaAlta (7.3)0.92%—Maccms19/4/202417/6/2026
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
AnalizadaAlta (8.8)0.88%—Publiccms16/4/202417/6/2026
An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
AnalizadaMedia (6.9)0.32%—Publiccms26/3/202417/6/2026
A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted…
ModificadaMedia (5.4)0.30%—Publiccms10/1/202417/6/2026
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.
ModificadaCrítica (9.8)1.5%—Publiccms20/11/202317/6/2026
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
ModificadaMedia (6.5)0.65%—Publiccms16/11/202317/6/2026
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
ModificadaAlta (8.8)0.64%—Chshcms Mccms17/9/202317/6/2026
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of…
ModificadaCrítica (9.8)1.0%💥 PoCPubliccms15/6/202317/6/2026
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
Orbitaley — Vulnerabilidades