Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.70%—Chshcms Mccms14/6/202317/6/2026
A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaAlta (8.8)0.70%—Chshcms Mccms14/6/202317/6/2026
A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed…
ModificadaMedia (6.5)0.87%—Chshcms Mccms28/4/202317/6/2026
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
ModificadaCrítica (9.8)0.98%—Chshcms Mccms28/4/202317/6/2026
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
ModificadaAlta (8.8)0.29%—Chshcms Mccms28/4/202317/6/2026
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
ModificadaCrítica (9.8)1.1%—Publiccms4/4/202317/6/2026
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.
ModificadaCrítica (9.8)1.1%—Publiccms4/4/202317/6/2026
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.
ModificadaAlta (8.8)0.87%💥 PoCMaccms1/2/202317/6/2026
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.
ModificadaMedia (6.1)0.50%💥 PoCMaccms6/1/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.
ModificadaMedia (6.1)0.44%—Publiccms11/11/202217/6/2026
A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is…
ModificadaCrítica (9.8)1.1%—Publiccms2/9/202217/6/2026
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
ModificadaMedia (6.5)0.69%—Maccms17/8/202217/6/2026
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
ModificadaMedia (5.4)0.43%—Maccms21/6/202217/6/2026
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
ModificadaMedia (5.4)0.43%—Maccms21/6/202217/6/2026
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
ModificadaMedia (5.3)1.1%—Publiccms3/6/202217/6/2026
PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.
ModificadaMedia (6.1)0.64%—Maccms31/3/202217/6/2026
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
ModificadaMedia (6.1)0.56%—Maccms25/3/202217/6/2026
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.
ModificadaMedia (6.1)0.56%—Maccms25/3/202217/6/2026
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.
ModificadaMedia (6.1)0.56%—Maccms25/3/202217/6/2026
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters.
ModificadaMedia (6.1)0.56%—Maccms25/3/202217/6/2026
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.
ModificadaMedia (6.1)0.57%—Maccms25/3/202217/6/2026
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.
ModificadaAlta (7.5)0.80%—Idccms21/3/202217/6/2026
idcCMS v1.10 was discovered to contain an issue which allows attackers to arbitrarily delete the install.lock file, resulting in a reset of the CMS settings and data.
ModificadaMedia (5.4)0.46%—Maccms16/3/202217/6/2026
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.
ModificadaCrítica (9.8)1.2%—Maccms16/3/202217/6/2026
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
ModificadaCrítica (9.8)22%—Publiccms14/2/202217/6/2026
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
Orbitaley — Vulnerabilidades