Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.73%—Yzmcms19/11/202017/6/2026
In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.
ModificadaMedia (6.1)1.2%—Yzmcms26/9/201917/6/2026
An HTTP Host header injection vulnerability exists in YzmCMS V5.3. A malicious user can poison a web cache or trigger redirections.
ModificadaMedia (6.5)0.66%—Yzmcms21/9/201917/6/2026
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
ModificadaCrítica (9.8)2.0%—Zzcms Zzmcms19/7/201917/6/2026
zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php.
ModificadaMedia (5.4)0.62%—Yzmcms20/6/201917/6/2026
YzmCMS 5.1 has XSS via the admin/system_manage/user_config_add.html title parameter.
ModificadaAlta (7.2)1.3%—Sem-cms Semcms25/4/201917/6/2026
An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inject_check_sql protection mechanism is incomplete.
ModificadaMedia (4.8)0.68%—Yzmcms11/3/201917/6/2026
Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter,
ModificadaMedia (4.8)0.68%—Yzmcms11/3/201917/6/2026
Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter.
ModificadaMedia (4.8)0.67%—Yzmcms5/3/201917/6/2026
An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, related to the site_code parameter.
ModificadaMedia (4.8)0.56%—Sem-cms Semcms10/12/201817/6/2026
SEMCMS 3.5 has XSS via the first text box to the SEMCMS_Main.php URI.
ModificadaAlta (8.8)0.52%—Yzmcms10/12/201817/6/2026
YzmCMS v5.2 has admin/role/add.html CSRF.
ModificadaMedia (4.8)0.49%—Yzmcms4/12/201817/6/2026
An issue was discovered in YzmCMS 5.2. XSS exists via the admin/content/search.html searinfo parameter.
ModificadaMedia (6.1)0.86%—Yzmcms7/11/201817/6/2026
An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie.
ModificadaMedia (4.8)0.53%—Sem-cms Semcms30/10/201817/6/2026
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
ModificadaMedia (5.4)0.56%—Sem-cms Semcms30/10/201817/6/2026
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
ModificadaAlta (7.5)1.5%—Mingsoft Mcms30/10/201817/6/2026
An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.
ModificadaCrítica (9.8)1.2%—Mingsoft Mcms30/10/201817/6/2026
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename, and then intercept the data packet. In…
ModificadaMedia (6.1)0.80%—Sem-cms Semcms29/10/201817/6/2026
XSS was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing.
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI.
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI.
ModificadaAlta (8.8)0.52%—Sem-cms Semcms29/10/201817/6/2026
A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing.
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI.
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.
Orbitaley — Vulnerabilidades