Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.73% | — | Yzmcms | 19/11/2020 | 17/6/2026 | In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 1.2% | — | Yzmcms | 26/9/2019 | 17/6/2026 | An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections. | |
| Modificada | Media (6.5) | 0.66% | — | Yzmcms | 21/9/2019 | 17/6/2026 | admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route. | |
| Modificada | Crítica (9.8) | 2.0% | — | Zzcms Zzmcms | 19/7/2019 | 17/6/2026 | zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php. | |
| Modificada | Media (5.4) | 0.62% | — | Yzmcms | 20/6/2019 | 17/6/2026 | YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter. | |
| Modificada | Alta (7.2) | 1.3% | — | Sem-cms Semcms | 25/4/2019 | 17/6/2026 | An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete. | |
| Modificada | Media (4.8) | 0.68% | — | Yzmcms | 11/3/2019 | 17/6/2026 | Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter, | |
| Modificada | Media (4.8) | 0.68% | — | Yzmcms | 11/3/2019 | 17/6/2026 | Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter. | |
| Modificada | Media (4.8) | 0.67% | — | Yzmcms | 5/3/2019 | 17/6/2026 | An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter. | |
| Modificada | Media (4.8) | 0.56% | — | Sem-cms Semcms | 10/12/2018 | 17/6/2026 | SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI. | |
| Modificada | Alta (8.8) | 0.52% | — | Yzmcms | 10/12/2018 | 17/6/2026 | YzmCMS v5.2 has admin/role/add.html CSRF. | |
| Modificada | Media (4.8) | 0.49% | — | Yzmcms | 4/12/2018 | 17/6/2026 | An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Yzmcms | 7/11/2018 | 17/6/2026 | An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 30/10/2018 | 17/6/2026 | XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter. | |
| Modificada | Media (5.4) | 0.56% | — | Sem-cms Semcms | 30/10/2018 | 17/6/2026 | XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Mingsoft Mcms | 30/10/2018 | 17/6/2026 | An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Mingsoft Mcms | 30/10/2018 | 17/6/2026 | An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename, and then intercept the data packet. In… | |
| Modificada | Media (6.1) | 0.80% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI. | |
| Modificada | Alta (8.8) | 0.52% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI. | |
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field. |