Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.82% | — | Yzmcms | 28/1/2022 | 17/6/2026 | YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html. | |
| Modificada | Media (6.5) | 0.74% | — | Yzmcms | 28/1/2022 | 17/6/2026 | YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete. | |
| Modificada | Alta (7.5) | 1.5% | — | Mingsoft Mcms | 26/1/2022 | 17/6/2026 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive… | |
| Modificada | Crítica (9.8) | 3.1% | — | Mingsoft Mcms | 26/1/2022 | 17/6/2026 | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload. | |
| Modificada | Alta (7.5) | 1.6% | — | Mingsoft Mcms | 26/1/2022 | 17/6/2026 | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive… | |
| Modificada | Crítica (9.8) | 1.8% | — | Mingsoft Mcms | 21/1/2022 | 17/6/2026 | MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mingsoft Mcms | 21/1/2022 | 17/6/2026 | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do. | |
| Modificada | Crítica (9.8) | 24% | — | Mingsoft Mcms | 21/1/2022 | 17/6/2026 | A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload. | |
| Modificada | Crítica (9.8) | 2.6% | — | Mingsoft Mcms | 21/1/2022 | 17/6/2026 | MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file. | |
| Modificada | Crítica (9.8) | 2.5% | — | Mingsoft Mcms | 21/1/2022 | 17/6/2026 | MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.1% | — | Sem-cms Semcms | 17/12/2021 | 17/6/2026 | The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query. | |
| Modificada | Crítica (9.8) | 1.0% | — | Sem-cms Semcms | 17/12/2021 | 17/6/2026 | A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password. | |
| Modificada | Alta (8.8) | 0.56% | — | Yzmcms | 23/9/2021 | 17/6/2026 | A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application. | |
| Modificada | Media (4.8) | 0.59% | — | Yzmcms | 23/9/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Media (4.8) | 0.59% | — | Yzmcms | 23/9/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Alta (7.5) | 1.3% | — | Yzmcms | 1/9/2021 | 17/6/2026 | YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function. | |
| Modificada | Media (5.4) | 0.52% | — | Yzmcms | 30/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html. | |
| Modificada | Media (4.3) | 0.57% | — | Yzmcms | 3/6/2021 | 17/6/2026 | An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html. | |
| Modificada | Media (5.4) | 0.50% | — | Yzmcms | 3/6/2021 | 17/6/2026 | A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page. | |
| Modificada | Alta (7.5) | 1.3% | — | Yzmcms | 3/6/2021 | 17/6/2026 | An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read. | |
| Modificada | Media (5.4) | 0.73% | — | Yzmcms | 10/5/2021 | 17/6/2026 | In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML. | |
| Modificada | Media (6.1) | 0.87% | — | Yzmcms | 10/5/2021 | 17/6/2026 | In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3. | |
| Modificada | Media (6.1) | 1.3% | — | Yzmcms | 30/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mingsoft Mcms | 26/1/2021 | 17/6/2026 | An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do. | |
| Modificada | Crítica (9.8) | 71% | 💥 Exploit | Incomcms Project Incomcms | 7/12/2020 | 17/6/2026 | IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server. |