Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

166 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.67%—Cxuucms27/12/202017/6/2026
CXUUCMS V3 allows class="layui-input" XSS.
ModificadaMedia (6.5)0.44%—Cxuucms26/12/202017/6/2026
CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add.
ModificadaMedia (4.8)0.66%—Cxuucms26/12/202017/6/2026
CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of admin.php?c=content&a=add.
ModificadaCrítica (9.8)1.9%—Ucms Project Ucms30/11/202017/6/2026
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
ModificadaAlta (7.5)3.8%💥 ExploitCxuucms18/11/202017/6/2026
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php.
ModificadaCrítica (9.8)8.6%—Ucms Project Ucms23/10/202017/6/2026
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
ModificadaAlta (8.8)0.60%—Eyoucms22/10/202017/6/2026
A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php.
ModificadaMedia (5.3)0.95%—Ucms Project Ucms4/9/202017/6/2026
An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly accessing the website built by UCMS.
ModificadaMedia (4.8)0.61%—Hotarucms12/10/201917/6/2026
A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (aka SITE_NAME), a related issue to CVE-2011-4709.1.
ModificadaMedia (6.1)0.98%—Eyoucms10/10/201917/6/2026
EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
ModificadaAlta (8.8)1.2%—Ucms Project Ucms21/5/201917/6/2026
sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.
ModificadaMedia (6.1)0.83%—Ucms Project Ucms7/3/201917/6/2026
An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.
ModificadaMedia (6.1)0.68%—Yunucms4/1/201917/6/2026
An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/index/show/index cw parameter.
ModificadaMedia (6.1)0.68%—Yunucms4/1/201917/6/2026
YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request.
ModificadaMedia (4.8)0.56%—Ucms Project Ucms30/12/201817/6/2026
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
ModificadaMedia (6.1)0.71%—Ucms Project Ucms30/12/201817/6/2026
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
ModificadaAlta (8.8)1.5%—Ucms Project Ucms30/12/201817/6/2026
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
ModificadaAlta (8.8)0.53%—Ucms Project Ucms30/12/201817/6/2026
UCMS 1.4.7 has ?do=user_addpost CSRF.
ModificadaMedia (4.8)0.55%—Ucms Project Ucms30/12/201817/6/2026
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
ModificadaAlta (8.8)1.1%—Ucms Project Ucms22/11/201817/6/2026
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
ModificadaAlta (7.5)1.4%—Yunucms11/11/201817/6/2026
statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file.
ModificadaCrítica (9.8)1.5%—Yunucms11/11/201817/6/2026
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.
ModificadaAlta (7.5)0.89%—Lulucms Lulu CMS29/10/201817/6/2026
An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code into the three text input fields.
ModificadaMedia (4.8)0.56%—Yunucms29/10/201817/6/2026
An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5.
ModificadaMedia (4.8)0.56%—Yunucms29/10/201817/6/2026
An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5.
Orbitaley — Vulnerabilidades