Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.51%—Feehicms15/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.
ModificadaMedia (5.4)0.51%—Feehicms15/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.
ModificadaMedia (5.4)0.51%—Feehicms15/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.
ModificadaMedia (5.4)0.51%—Feehicms15/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page.
ModificadaMedia (5.4)0.47%—Feehicms15/12/202217/6/2026
File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.
ModificadaMedia (6.1)0.43%—Feehicms15/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page.
ModificadaMedia (6.1)0.65%—Feehicms15/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
ModificadaMedia (6.1)0.59%—Feehicms15/12/202217/6/2026
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
ModificadaAlta (8.8)0.76%—Jizhicms23/11/202217/6/2026
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.
ModificadaAlta (8.8)0.76%—Jizhicms23/11/202217/6/2026
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
ModificadaAlta (8.8)0.32%—Jizhicms23/11/202217/6/2026
An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admin/adminadd.html
ModificadaMedia (4.3)0.21%—Feehicms16/11/202217/6/2026
A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier of this vulnerability is VDB-213788.
ModificadaMedia (6.1)0.43%—Feehicms9/11/202217/6/2026
FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.
ModificadaCrítica (9.8)0.50%—Easyiicms31/10/202217/6/2026
A vulnerability, which was classified as critical, has been found in easyii CMS. This issue affects the function file of the file helpers/Upload.php of the component File Upload Management. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The identifier VDB-212501 was assigned to…
ModificadaCrítica (9.8)0.96%—Idreamsoft Icms13/10/202217/6/2026
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
ModificadaMedia (5.4)0.49%—Feehicms29/9/202217/6/2026
FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.
ModificadaCrítica (9.8)1.2%—Feehicms6/9/202217/6/2026
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
ModificadaBaja (2.7)0.96%—Wuzhicms26/8/202217/6/2026
A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:
ModificadaCrítica (9.8)0.91%—Jizhicms19/8/202217/6/2026
jizhicms v2.3.1 has SQL injection in the background.
ModificadaAlta (8.8)0.40%—Jizhicms19/8/202217/6/2026
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
ModificadaAlta (8.8)0.45%—Xunruicms19/8/202217/6/2026
XunRuiCMS V4.5.6 is vulnerable to Cross Site Request Forgery (CSRF).
ModificadaMedia (6.1)0.77%—Wuzhicms28/6/202217/6/2026
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
ModificadaCrítica (9.8)1.6%—1234n Minicms28/6/202217/6/2026
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
ModificadaAlta (8.1)0.41%—1234n Minicms24/6/202217/6/2026
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
ModificadaCrítica (9.8)1.1%—Wuzhicms16/6/202217/6/2026
SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php