Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Mingsoft Mcms | 11/5/2022 | 17/6/2026 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mingsoft Mcms | 2/5/2022 | 17/6/2026 | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do. | |
| Modificada | Alta (8.8) | 0.67% | — | Mingsoft Mcms | 22/4/2022 | 17/6/2026 | MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data. | |
| Modificada | Crítica (9.8) | 1.4% | — | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php | |
| Modificada | Crítica (9.8) | 1.4% | — | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php | |
| Modificada | Crítica (9.8) | 1.4% | — | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php | |
| Modificada | Crítica (9.8) | 5.3% | 💥 Exploit | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php | |
| Modificada | Crítica (9.8) | 5.9% | 💥 Exploit | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php | |
| Modificada | Crítica (9.8) | 5.5% | 💥 Exploit | Mingsoft Mcms | 5/4/2022 | 17/6/2026 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list. | |
| Modificada | Media (5.4) | 1.5% | 💥 Exploit | Thedigitalcraft Atomcms | 15/3/2022 | 17/6/2026 | Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php. | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | Thedigitalcraft Atomcms | 15/3/2022 | 17/6/2026 | Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php. | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Thedigitalcraft Atomcms | 15/3/2022 | 17/6/2026 | Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php. | |
| Modificada | Crítica (9.1) | 1.2% | — | Yzmcms | 10/3/2022 | 9/7/2026 | YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home pages through the non login status because… | |
| Modificada | Crítica (9.8) | 2.2% | — | Mingsoft Mcms | 4/3/2022 | 17/6/2026 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to… | |
| Modificada | Crítica (9.8) | 7.0% | 💥 Exploit | Mingsoft Mcms | 3/3/2022 | 17/6/2026 | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mingsoft Mcms | 3/3/2022 | 17/6/2026 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java. | |
| Modificada | Crítica (9.8) | 7.7% | 💥 Exploit | Mingsoft Mcms | 3/3/2022 | 17/6/2026 | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. | |
| Modificada | Crítica (9.1) | 2.7% | — | Mingsoft Mcms | 18/2/2022 | 17/6/2026 | MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module. | |
| Modificada | Alta (7.1) | 0.77% | — | Mingsoft Mcms | 18/2/2022 | 17/6/2026 | MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName. | |
| Modificada | Alta (8.1) | 1.0% | — | Mingsoft Mcms | 18/2/2022 | 17/6/2026 | MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do. | |
| Modificada | Crítica (9.8) | 3.7% | — | Mingsoft Mcms | 18/2/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.4% | — | Mingsoft Mcms | 17/2/2022 | 17/6/2026 | A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do | |
| Modificada | Alta (8.8) | 0.54% | — | Yzmcms | 15/2/2022 | 17/6/2026 | YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add | |
| Modificada | Crítica (9.8) | 62% | 💥 Exploit | Thedigitalcraft Atomcms | 1/2/2022 | 17/6/2026 | AtomCMS v2.0 was discovered to contain a SQL injection vulnerability via /admin/login.php. | |
| Modificada | Media (5.3) | 1.1% | — | Yzmcms | 28/1/2022 | 17/6/2026 | The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments. |