Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.58% | — | Publiccms | 26/5/2018 | 17/6/2026 | An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account. | |
| Modificada | Crítica (9.8) | 44% | — | Maccms | 18/12/2017 | 17/6/2026 | Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request. | |
| Modificada | Crítica (9.8) | 2.3% | — | Siemens Ccid1445-dn18 FirmwareSiemens Ccid1445-dn28 FirmwareSiemens Ccid1445-dn36 FirmwareSiemens Ccis1425 Firmware+11 | 22/11/2016 | 17/6/2026 | The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-DN36, CFIS1425, CCIS1425, CFMS2025, CCMS2025, CVMS2025-IR, CFMW1025, CCMW1025… | |
| Modificada | Alta (7.5) | 2.1% | — | SAP Ccms Agent | 10/4/2014 | 17/6/2026 | An unspecified RFC function in SAP CCMS Agent allows remote attackers to execute arbitrary commands via unknown vectors. | |
| Modificada | Media (5) | 0.98% | — | SAP Ccms / Database Monitor | 10/4/2014 | 17/6/2026 | Unspecified vulnerability in the SAP CCMS / Database Monitors for Oracle allows attackers to obtain the database password via unknown vectors. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Paul Arbogast Accms | 25/8/2009 | 16/6/2026 | All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database configuration information, including credentials, via a direct request to accms.dat. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Sebraccms | 21/11/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors. | |
| Modificada | Alta (10) | 3.5% | 💥 Exploit | Customcms Ccms | 9/10/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php, (2) forums.php, (3) admin.php, (4) header.php, (5) pages/story.php and (6) pages/poll.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Customcms Ccms | 4/1/2008 | 16/6/2026 | SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Inccms Technology Inccms Core | 17/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter. |