Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Foru CMS Project Foru CMS | 27/9/2023 | 17/6/2026 | A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/index.php. The manipulation of the argument db_name leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product… | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Macs CMS Project Macs CMS | 27/9/2023 | 17/6/2026 | In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account. | |
| Modificada | Media (5.3) | 12% | 💥 Exploit | Jfinalcms Project Jfinalcms | 19/9/2023 | 17/6/2026 | An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal. | |
| Modificada | Media (6.1) | 0.48% | — | Ucms Project Ucms | 17/9/2023 | 17/6/2026 | A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file ajax.php?do=strarraylist. The manipulation of the argument strdefault leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (7.2) | 0.92% | — | Supermicro-cms Project Supermicro-cms | 11/8/2023 | 17/6/2026 | An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php. | |
| Modificada | Media (4.9) | 0.55% | — | Supermicro-cms Project Supermicro-cms | 11/8/2023 | 17/6/2026 | An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php. | |
| Modificada | Media (6.1) | 0.41% | — | CMS Project CMS | 31/7/2023 | 17/6/2026 | Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java. | |
| Modificada | Media (6.1) | 0.41% | — | CMS Project CMS | 31/7/2023 | 17/6/2026 | Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java. | |
| Modificada | Media (5.4) | 0.49% | — | Duxcms Project Duxcms | 31/7/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in DuxCMS 2.1 allows remote attackers to run arbitrary code via the content, time, copyfrom parameters when adding or editing a post. | |
| Modificada | Media (6.5) | 0.34% | — | Duxcms Project Duxcms | 31/7/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/content/add. | |
| Modificada | Alta (8.1) | 0.96% | — | Duxcms Project Duxcms | 6/7/2023 | 17/6/2026 | Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del. | |
| Modificada | Alta (8.8) | 0.71% | — | Duxcms Project Duxcms | 6/7/2023 | 17/6/2026 | File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload. | |
| Modificada | Media (4.8) | 0.43% | — | Chaoji CMS Project Chaoji CMS | 27/6/2023 | 17/6/2026 | Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via /index.php?admin-master-webset. | |
| Modificada | Media (6.8) | 0.32% | — | Catfishcms Project Catfishcms | 27/6/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions via /index.php/admin/index/modifymanage.html. | |
| Modificada | Media (4.8) | 0.43% | — | Chaoji CMS Project Chaoji CMS | 27/6/2023 | 17/6/2026 | Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code. | |
| Modificada | Media (4.8) | 0.39% | — | Chaoji CMS Project Chaoji CMS | 27/6/2023 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges. | |
| Modificada | Alta (8.8) | 0.43% | — | Hongcms Project Hongcms | 20/6/2023 | 17/6/2026 | Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter. | |
| Modificada | Media (5.4) | 0.55% | — | Yiicms Project Yiicms | 20/6/2023 | 17/6/2026 | Cross Site Scripting vulnerability in YiiCMS v.1.0 allows a remote attacker to execute arbitrary code via the news function. | |
| Modificada | Alta (7.5) | 0.74% | — | Joyplus-cms Project Joyplus-cms | 20/6/2023 | 17/6/2026 | SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function. | |
| Modificada | Media (6.1) | 0.41% | — | Tp5cms Project Tp5cms | 14/6/2023 | 17/6/2026 | An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the keywords parameter. | |
| Modificada | Crítica (9.1) | 0.80% | — | Imperial CMS Project Imperial CMS | 7/6/2023 | 17/6/2026 | Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp/ListSp.php. This vulnerability is exploited by attackers via a crafted POST request. | |
| Modificada | Crítica (9.8) | 0.75% | — | Bluecms Project Bluecms | 30/5/2023 | 17/6/2026 | BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php. | |
| Modificada | Media (5.4) | 0.60% | — | Sucms Project Sucms | 17/5/2023 | 17/6/2026 | A vulnerability was found in Sucms 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin_ads.php?action=add. The manipulation of the argument intro leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (8.8) | 0.34% | — | Flycms Project Flycms | 8/5/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in FlyCms 1.0 allows attackers to add arbitrary administrator accounts via system/admin/admin_save. | |
| Modificada | Crítica (9.8) | 0.84% | — | Victor CMS Project Victor CMS | 8/5/2023 | 17/6/2026 | SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request. |