Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.70% | — | Chshcms Mccms | 14/6/2023 | 17/6/2026 | A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.70% | — | Chshcms Mccms | 14/6/2023 | 17/6/2026 | A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed… | |
| Modificada | Media (6.5) | 0.87% | — | Chshcms Mccms | 28/4/2023 | 17/6/2026 | An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters. | |
| Modificada | Crítica (9.8) | 0.98% | — | Chshcms Mccms | 28/4/2023 | 17/6/2026 | SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | |
| Modificada | Alta (8.8) | 0.29% | — | Chshcms Mccms | 28/4/2023 | 17/6/2026 | mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Crítica (9.8) | 1.1% | — | Publiccms | 4/4/2023 | 17/6/2026 | SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl. | |
| Modificada | Crítica (9.8) | 1.1% | — | Publiccms | 4/4/2023 | 17/6/2026 | SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter. | |
| Modificada | Alta (8.8) | 0.87% | 💥 PoC | Maccms | 1/2/2023 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module. | |
| Modificada | Media (6.1) | 0.50% | 💥 PoC | Maccms | 6/1/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module. | |
| Modificada | Media (6.1) | 0.44% | — | Publiccms | 11/11/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is… | |
| Modificada | Crítica (9.8) | 1.1% | — | Publiccms | 2/9/2022 | 17/6/2026 | Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage. | |
| Modificada | Media (6.5) | 0.69% | — | Maccms | 17/8/2022 | 17/6/2026 | maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html. | |
| Modificada | Media (5.4) | 0.43% | — | Maccms | 21/6/2022 | 17/6/2026 | maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | |
| Modificada | Media (5.4) | 0.43% | — | Maccms | 21/6/2022 | 17/6/2026 | maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | |
| Modificada | Media (5.3) | 1.1% | — | Publiccms | 3/6/2022 | 17/6/2026 | PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java. | |
| Modificada | Media (6.1) | 0.64% | — | Maccms | 31/3/2022 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Maccms | 25/3/2022 | 17/6/2026 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Maccms | 25/3/2022 | 17/6/2026 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter. | |
| Modificada | Media (6.1) | 0.56% | — | Maccms | 25/3/2022 | 17/6/2026 | Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters. | |
| Modificada | Media (6.1) | 0.56% | — | Maccms | 25/3/2022 | 17/6/2026 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter. | |
| Modificada | Media (6.1) | 0.57% | — | Maccms | 25/3/2022 | 17/6/2026 | Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters. | |
| Modificada | Alta (7.5) | 0.80% | — | Idccms | 21/3/2022 | 17/6/2026 | idcCMS v1.10 was discovered to contain an issue which allows attackers to arbitrarily delete the install.lock file, resulting in a reset of the CMS settings and data. | |
| Modificada | Media (5.4) | 0.46% | — | Maccms | 16/3/2022 | 17/6/2026 | There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks. | |
| Modificada | Crítica (9.8) | 1.2% | — | Maccms | 16/3/2022 | 17/6/2026 | In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges. | |
| Modificada | Crítica (9.8) | 22% | — | Publiccms | 14/2/2022 | 17/6/2026 | PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. |