Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
161 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.84% | — | Craftcms Craft CMS | 11/10/2019 | 17/6/2026 | Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion. | |
| Modificada | Media (5.3) | 9.4% | 💥 Exploit | Craftcms Craft CMS | 26/7/2019 | 17/6/2026 | In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public. | |
| Modificada | Media (6.1) | 0.94% | — | Craftcms Craft CMS | 18/6/2019 | 17/6/2026 | Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. | |
| Modificada | Alta (7.2) | 1.5% | — | Craftcms Craft CMS | 25/12/2018 | 17/6/2026 | Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be… | |
| Modificada | Media (4.8) | 3.7% | 💥 Exploit | Craftcms Craft CMS | 24/12/2018 | 17/6/2026 | index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. | |
| Modificada | Alta (8.8) | 1.9% | — | Craftcms Craft CMS | 1/1/2018 | 17/6/2026 | Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension. | |
| Modificada | Media (5.4) | 2.8% | 💥 Exploit | Craftcms Craft CMS | 8/6/2017 | 17/6/2026 | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. | |
| Modificada | Media (5.3) | 0.96% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message. | |
| Modificada | Media (6.1) | 0.84% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052. | |
| Modificada | Media (5.3) | 1.2% | — | Craftcms Craft CMS | 1/5/2017 | 17/6/2026 | Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. | |
| Modificada | Media (6.1) | 0.83% | — | Craftcms Craft CMS | 22/4/2017 | 17/6/2026 | Craft CMS before 2.6.2974 allows XSS attacks. |