Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

186 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.1%—Zzcms9/12/202117/6/2026
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.
ModificadaAlta (8.8)1.1%—Zzcms9/12/202117/6/2026
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.
ModificadaAlta (7.2)1.1%—Zzcms9/12/202117/6/2026
An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.
ModificadaAlta (7.2)1.1%—Zzcms9/12/202117/6/2026
An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.
ModificadaCrítica (9.8)1.2%—Cszcms CSZ CMS27/10/202117/6/2026
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
ModificadaAlta (7.5)1.7%—Zzcms14/10/20219/7/2026
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.
ModificadaAlta (7.5)1.5%—Zzcms14/10/202117/6/2026
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie.
ModificadaAlta (7.5)1.5%—Zzcms14/10/202117/6/2026
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie.
ModificadaAlta (7.5)1.5%—Zzcms14/10/202117/6/2026
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.
ModificadaAlta (7.2)2.8%—Zzcms26/8/202117/6/2026
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
ModificadaCrítica (9.8)0.99%—Thinkphp-zcms Project Thinkphp-zcms26/8/202117/6/2026
thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
ModificadaCrítica (9.1)1.3%—Cszcms CSZ CMS30/7/202117/6/2026
CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization.
ModificadaMedia (5.4)0.45%—Cszcms CSZ CMS9/7/202117/6/2026
A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Article' field under the 'Article' plugin.
ModificadaMedia (5.4)0.45%—Cszcms CSZ CMS9/7/202117/6/2026
A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Pages' field under the 'Pages Content' module.
ModificadaMedia (5.4)0.61%—Zzcms3/6/202117/6/2026
An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.
ModificadaCrítica (9.8)1.7%—Zzcms24/5/202117/6/2026
An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.
ModificadaAlta (7.5)1.2%—Zzcms13/5/202117/6/2026
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
ModificadaCrítica (9.8)3.8%—Zzzcms Zzzphp11/5/202117/6/2026
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.
ModificadaCrítica (9.8)3.7%—Zzcms8/4/202117/6/2026
zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.
ModificadaCrítica (9.8)2.1%—Zzzcms Zzzphp15/3/202117/6/2026
A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass.
ModificadaMedia (5.4)0.53%—Cszcms CSZ CMS11/3/202117/6/2026
CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
ModificadaMedia (5.4)0.54%—Cszcms CSZ CMS10/3/202117/6/2026
A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter.
ModificadaCrítica (9.8)3.6%—Zzzcms Zzzphp5/2/202117/6/2026
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
ModificadaAlta (8.8)1.2%—Zzcms11/1/20219/7/2026
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
ModificadaCrítica (9.8)2.7%—Zzzcms Zzzphp18/12/202017/6/2026
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.