Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.67% | — | Cxuucms | 27/12/2020 | 17/6/2026 | CXUUCMS V3 allows class="layui-input" XSS. | |
| Modificada | Media (6.5) | 0.44% | — | Cxuucms | 26/12/2020 | 17/6/2026 | CXUUCMS V3 3.1 has a CSRF vulnerability that can add an administrator account via admin.php?c=adminuser&a=add. | |
| Modificada | Media (4.8) | 0.66% | — | Cxuucms | 26/12/2020 | 17/6/2026 | CXUUCMS V3 3.1 is affected by a reflected XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the imgurl parameter of admin.php?c=content&a=add. | |
| Modificada | Crítica (9.8) | 1.9% | — | Ucms Project Ucms | 30/11/2020 | 17/6/2026 | File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Cxuucms | 18/11/2020 | 17/6/2026 | cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parameter via search.php. | |
| Modificada | Crítica (9.8) | 8.6% | — | Ucms Project Ucms | 23/10/2020 | 17/6/2026 | An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server. | |
| Modificada | Alta (8.8) | 0.60% | — | Eyoucms | 22/10/2020 | 17/6/2026 | A CSRF vulnerability in Eyoucms v1.2.7 allows an attacker to add an admin account via login.php. | |
| Modificada | Media (5.3) | 0.95% | — | Ucms Project Ucms | 4/9/2020 | 17/6/2026 | An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly accessing the website built by UCMS. | |
| Modificada | Media (4.8) | 0.61% | — | Hotarucms | 12/10/2019 | 17/6/2026 | A stored XSS vulnerability was discovered in Hotaru CMS v1.7.2 via the admin_index.php?page=settings SITE NAME field (aka SITE_NAME), a related issue to CVE-2011-4709.1. | |
| Modificada | Media (6.1) | 0.98% | — | Eyoucms | 10/10/2019 | 17/6/2026 | EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Ucms Project Ucms | 21/5/2019 | 17/6/2026 | sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter. | |
| Modificada | Media (6.1) | 0.83% | — | Ucms Project Ucms | 7/3/2019 | 17/6/2026 | An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request. | |
| Modificada | Media (6.1) | 0.68% | — | Yunucms | 4/1/2019 | 17/6/2026 | An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/index/show/index cw parameter. | |
| Modificada | Media (6.1) | 0.68% | — | Yunucms | 4/1/2019 | 17/6/2026 | YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request. | |
| Modificada | Media (4.8) | 0.56% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action. | |
| Modificada | Media (6.1) | 0.71% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action. | |
| Modificada | Alta (8.8) | 1.5% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action. | |
| Modificada | Alta (8.8) | 0.53% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | UCMS 1.4.7 has ?do=user_addpost CSRF. | |
| Modificada | Media (4.8) | 0.55% | — | Ucms Project Ucms | 30/12/2018 | 17/6/2026 | UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action. | |
| Modificada | Alta (8.8) | 1.1% | — | Ucms Project Ucms | 22/11/2018 | 17/6/2026 | UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty. | |
| Modificada | Alta (7.5) | 1.4% | — | Yunucms | 11/11/2018 | 17/6/2026 | statics/ueditor/php/vendor/Local.class.php in YUNUCMS 1.1.5 allows arbitrary file deletion via the statics/ueditor/php/controller.php?action=remove key parameter, as demonstrated by using directory traversal to delete the install.lock file. | |
| Modificada | Crítica (9.8) | 1.5% | — | Yunucms | 11/11/2018 | 17/6/2026 | statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php. | |
| Modificada | Alta (7.5) | 0.89% | — | Lulucms Lulu CMS | 29/10/2018 | 17/6/2026 | An issue was discovered in LuLu CMS through 2015-05-14. backend\modules\filemanager\controllers\DefaultController.php allows arbitrary file upload by entering a filename, directory name, and PHP code into the three text input fields. | |
| Modificada | Media (4.8) | 0.56% | — | Yunucms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5. | |
| Modificada | Media (4.8) | 0.56% | — | Yunucms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5. |