Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.82%—Yzmcms28/1/202217/6/2026
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html.
ModificadaMedia (6.5)0.74%—Yzmcms28/1/202217/6/2026
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin_manage/delete.
ModificadaAlta (7.5)1.5%—Mingsoft Mcms26/1/202217/6/2026
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive…
ModificadaCrítica (9.8)3.1%—Mingsoft Mcms26/1/202217/6/2026
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
ModificadaAlta (7.5)1.6%—Mingsoft Mcms26/1/202217/6/2026
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive…
ModificadaCrítica (9.8)1.8%—Mingsoft Mcms21/1/202217/6/2026
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
ModificadaCrítica (9.8)1.6%—Mingsoft Mcms21/1/202217/6/2026
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
ModificadaCrítica (9.8)24%—Mingsoft Mcms21/1/202217/6/2026
A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.
ModificadaCrítica (9.8)2.6%—Mingsoft Mcms21/1/202217/6/2026
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.
ModificadaCrítica (9.8)2.5%—Mingsoft Mcms21/1/202217/6/2026
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
ModificadaAlta (7.5)1.1%—Sem-cms Semcms17/12/202117/6/2026
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.
ModificadaCrítica (9.8)1.0%—Sem-cms Semcms17/12/202117/6/2026
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
ModificadaAlta (8.8)0.56%—Yzmcms23/9/202117/6/2026
A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.
ModificadaMedia (4.8)0.59%—Yzmcms23/9/202117/6/2026
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
ModificadaMedia (4.8)0.59%—Yzmcms23/9/202117/6/2026
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
ModificadaAlta (7.5)1.3%—Yzmcms1/9/202117/6/2026
YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
ModificadaMedia (5.4)0.52%—Yzmcms30/7/202117/6/2026
Cross Site Scripting (XSS) vulnerabiity in YzmCMS 5.2 via the site_code parameter in admin/index/init.html.
ModificadaMedia (4.3)0.57%—Yzmcms3/6/202117/6/2026
An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.
ModificadaMedia (5.4)0.50%—Yzmcms3/6/202117/6/2026
A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.
ModificadaAlta (7.5)1.3%—Yzmcms3/6/202117/6/2026
An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.
ModificadaMedia (5.4)0.73%—Yzmcms10/5/202117/6/2026
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.
ModificadaMedia (6.1)0.87%—Yzmcms10/5/202117/6/2026
In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.
ModificadaMedia (6.1)1.3%—Yzmcms30/4/202117/6/2026
Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in.
ModificadaCrítica (9.8)1.1%—Mingsoft Mcms26/1/202117/6/2026
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
ModificadaCrítica (9.8)71%💥 ExploitIncomcms Project Incomcms7/12/202017/6/2026
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.