Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.4% | — | Eyoucms | 3/11/2021 | 17/6/2026 | SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php. | |
| Modificada | Crítica (9.1) | 1.2% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method. | |
| Modificada | Crítica (9.8) | 2.8% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method. | |
| Modificada | Crítica (9.8) | 3.3% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method. | |
| Modificada | Alta (8.8) | 3.2% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method. | |
| Modificada | Alta (8.1) | 0.83% | — | Myucms Project Myucms | 6/10/2021 | 17/6/2026 | Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method. | |
| Modificada | Media (5.4) | 0.50% | — | Ucms Project Ucms | 29/9/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields. | |
| Modificada | Media (6.1) | 1.0% | — | Wenkucms Project Wenkucms | 15/9/2021 | 17/6/2026 | Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'. | |
| Modificada | Media (6.1) | 3.6% | 💥 Exploit | Eyoucms | 7/9/2021 | 17/6/2026 | EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function. | |
| Modificada | Alta (7.5) | 1.5% | — | Eyoucms | 7/9/2021 | 17/6/2026 | Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories. | |
| Modificada | Media (6.1) | 1.2% | — | Eyoucms | 7/9/2021 | 17/6/2026 | A Cross-site scripting (XSS) vulnerability in Users in Qiong ICP EyouCMS 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the `title` parameter in bind_email function. | |
| Modificada | Crítica (9.8) | 2.4% | — | Eyoucms | 7/9/2021 | 17/6/2026 | eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function. | |
| Modificada | Media (5.4) | 0.63% | — | Eyoucms | 7/9/2021 | 17/6/2026 | Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to trigger Reflected XSS. | |
| Modificada | Alta (7.2) | 0.88% | — | Cxuucms | 27/8/2021 | 17/6/2026 | SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php. | |
| Modificada | Media (6.1) | 0.64% | — | Cxuucms | 23/8/2021 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in CXUUCMS 3.1 in the search and c parameters in (1) public/search.php and in the (2) c parameter in admin.php. | |
| Modificada | Media (5.4) | 0.45% | — | Eyoucms | 19/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area. | |
| Modificada | Alta (8.8) | 0.57% | — | Eyoucms | 19/8/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn. | |
| Modificada | Alta (8.8) | 0.60% | — | Eyoucms | 18/8/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn. | |
| Modificada | Media (6.1) | 1.5% | — | Eyoucms | 18/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in Eyoucms v1.4.7 and earlier via the addonfieldext parameter. | |
| Modificada | Media (4.8) | 0.53% | — | Yunucms | 12/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php. | |
| Modificada | Media (6.1) | 0.72% | — | Yunucms | 12/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the upurl function in Page.php. | |
| Modificada | Media (5.4) | 0.50% | — | Eyoucms | 10/8/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the web_attr_2 field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (5.4) | 0.53% | — | Eyoucms | 10/8/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the web_copyright field of Eyoucms v1.4.1 allows authenticated attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (5.3) | 0.93% | — | Ucms Project Ucms | 23/7/2021 | 17/6/2026 | UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php. | |
| Modificada | Media (6.1) | 0.67% | — | Cxuucms | 27/12/2020 | 17/6/2026 | CXUUCMS V3 allows XSS via the first and third input fields to /public/admin.php. |