Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Zzcms | 9/12/2021 | 17/6/2026 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users. | |
| Modificada | Alta (8.8) | 1.1% | — | Zzcms | 9/12/2021 | 17/6/2026 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users. | |
| Modificada | Alta (7.2) | 1.1% | — | Zzcms | 9/12/2021 | 17/6/2026 | An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php. | |
| Modificada | Alta (7.2) | 1.1% | — | Zzcms | 9/12/2021 | 17/6/2026 | An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php. | |
| Modificada | Crítica (9.8) | 1.2% | — | Cszcms CSZ CMS | 27/10/2021 | 17/6/2026 | CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php. | |
| Modificada | Alta (7.5) | 1.7% | — | Zzcms | 14/10/2021 | 9/7/2026 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Zzcms | 14/10/2021 | 17/6/2026 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendsms.php page cookie. | |
| Modificada | Alta (7.5) | 1.5% | — | Zzcms | 14/10/2021 | 17/6/2026 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the dlid parameter in the /dl/dl_sendmail.php page cookie. | |
| Modificada | Alta (7.5) | 1.5% | — | Zzcms | 14/10/2021 | 17/6/2026 | A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page. | |
| Modificada | Alta (7.2) | 2.8% | — | Zzcms | 26/8/2021 | 17/6/2026 | A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters. | |
| Modificada | Crítica (9.8) | 0.99% | — | Thinkphp-zcms Project Thinkphp-zcms | 26/8/2021 | 17/6/2026 | thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add. | |
| Modificada | Crítica (9.1) | 1.3% | — | Cszcms CSZ CMS | 30/7/2021 | 17/6/2026 | CSZ CMS 1.2.9 is vulnerable to Arbitrary File Deletion. This occurs in PHP when the unlink() function is called and user input might affect portions of or the whole affected parameter, which represents the path of the file to remove, without sufficient sanitization. | |
| Modificada | Media (5.4) | 0.45% | — | Cszcms CSZ CMS | 9/7/2021 | 17/6/2026 | A cross site scripting (XSS) vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Article' field under the 'Article' plugin. | |
| Modificada | Media (5.4) | 0.45% | — | Cszcms CSZ CMS | 9/7/2021 | 17/6/2026 | A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Pages' field under the 'Pages Content' module. | |
| Modificada | Media (5.4) | 0.61% | — | Zzcms | 3/6/2021 | 17/6/2026 | An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php. | |
| Modificada | Crítica (9.8) | 1.7% | — | Zzcms | 24/5/2021 | 17/6/2026 | An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Zzcms | 13/5/2021 | 17/6/2026 | Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php. | |
| Modificada | Crítica (9.8) | 3.8% | — | Zzzcms Zzzphp | 11/5/2021 | 17/6/2026 | zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block. | |
| Modificada | Crítica (9.8) | 3.7% | — | Zzcms | 8/4/2021 | 17/6/2026 | zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF. | |
| Modificada | Crítica (9.8) | 2.1% | — | Zzzcms Zzzphp | 15/3/2021 | 17/6/2026 | A SQL injection vulnerability in zzzphp v1.8.0 through /form/index.php?module=getjson may lead to a possible access restriction bypass. | |
| Modificada | Media (5.4) | 0.53% | — | Cszcms CSZ CMS | 11/3/2021 | 17/6/2026 | CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name. | |
| Modificada | Media (5.4) | 0.54% | — | Cszcms CSZ CMS | 10/3/2021 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in cszcms 1.2.9 exists in /admin/pages/new via the content parameter. | |
| Modificada | Crítica (9.8) | 3.6% | — | Zzzcms Zzzphp | 5/2/2021 | 17/6/2026 | SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php. | |
| Modificada | Alta (8.8) | 1.2% | — | Zzcms | 11/1/2021 | 9/7/2026 | A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection). | |
| Modificada | Crítica (9.8) | 2.7% | — | Zzzcms Zzzphp | 18/12/2020 | 17/6/2026 | Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands. |