Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Cruxsoftware Cruxcms | 13/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in manager/login.php in CruxSoftware CruxCMS 3.0, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the txtusername parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Modxcms Evolution | 15/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to AjaxSearch. | |
| Modificada | Alta (7.5) | 1.1% | — | Modxcms | 15/4/2010 | 16/6/2026 | SQL injection vulnerability in MODx Evolution before 1.0.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors related to WebLogin. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Jaxcms | 23/3/2010 | 16/6/2026 | Directory traversal vulnerability in index.php in jaxCMS 1.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Bloofoxcms | 31/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Databay Maxcms | 25/9/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code via a URL in the fm_includes_special parameter. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Databay Maxcms | 25/9/2009 | 16/6/2026 | Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to read arbitrary files via directory traversal sequences in the thCMS_root parameter. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Databay Maxcms | 25/9/2009 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) is_projectPath parameter to includes/InstantSite/inc.is_root.php; GLOBALS[thCMS_root] parameter to (2) classes/class.Tree.php, (3)… | |
| Modificada | Media (6.8) | 0.63% | — | Modxcms | 17/9/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords via manager/index.php. NOTE: due to the lack of details, it is not clear whether this is related to CVE-2008-5941. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Modxcms | 17/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachable from manager/index.php; (5) highlight, (6) id, (7) email, (8)… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Maxcms | 29/5/2009 | 16/6/2026 | SQL injection vulnerability in admin/admin_manager.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via an m_username cookie in an add action. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bokecc Maxcms | 22/5/2009 | 16/6/2026 | SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a digg action. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Flexcms | 7/4/2009 | 16/6/2026 | SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Flexcms | 11/2/2009 | 16/6/2026 | SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Modxcms | 22/1/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MODx before 0.9.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the preserveUrls function and (2) "username input." NOTE: vector 2 may be related to CVE-2008-5939. | |
| Modificada | Media (6) | 0.48% | — | Modxcms | 22/1/2009 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors. | |
| Modificada | Media (6.8) | 1.2% | — | Modxcms | 22/1/2009 | 16/6/2026 | SQL injection vulnerability in index.php in MODx 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the searchid parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Modxcms | 22/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the username field, possibly related to snippet.ditto.php. NOTE: some sources list the id parameter as being affected, but this is probably… | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Modxcms | 22/1/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the reflect_base parameter. | |
| Modificada | Alta (8.1) | 10% | 💥 Exploit | Bloofoxcms | 29/12/2008 | 16/6/2026 | Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to read arbitrary files via the (1) lang, (2) theme, and (3) module parameters. | |
| Modificada | Baja (2.6) | 1.6% | 💥 Exploit | Flexcms | 19/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Crux Software Cruxcms | 12/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Bloofoxcms | 23/1/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php. | |
| Modificada | Alta (7.8) | 3.7% | 💥 Exploit | Bloofoxcms | 23/1/2008 | 16/6/2026 | Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (6.4) | 3.2% | 💥 Exploit | Modxcms | 8/1/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files… |