Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

663 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.41%—Hongcms Project Hongcms28/4/202317/6/2026
Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.
ModificadaMedia (6.1)0.55%—Ucms Project Ucms26/4/202317/6/2026
A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file saddpost.php of the component Column Configuration. The manipulation of the argument strorder leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
ModificadaCrítica (9.8)1.3%💥 PoCHansuncms Project Hansuncms22/4/202317/6/2026
A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/controller.ashx?action=catchimage. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
ModificadaMedia (5.4)0.43%—Teacms Project Teacms20/4/202317/6/2026
Cross Site Scripting vulnerability found in TeaCMS storage allows attacker to cause a leak of sensitive information via the article title parameter.
ModificadaMedia (6.1)0.44%—Dircms Project Dircms18/4/202317/6/2026
DirCMS 6.0.0 has a Cross Site Scripting (XSS) vulnerability in the foreground.
ModificadaMedia (5.4)0.38%—Aerocms Project Aerocms14/4/202317/6/2026
AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaAlta (8.8)0.44%—Doyocms Project Doyocms11/4/202317/6/2026
Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the background system settings.
ModificadaCrítica (9.8)1.1%—Doyocms Project Doyocms11/4/202317/6/2026
File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.
ModificadaAlta (7.2)0.70%—Teacms Project Teacms4/4/202317/6/2026
An unauthorized access issue found in XiaoBingby TeaCMS 2.3.3 allows attackers to escalate privileges via the id and keywords parameter(s).
ModificadaAlta (8.1)0.81%—Muyucms Project Muyucms28/3/202317/6/2026
MuYuCMS v2.2 was discovered to contain an arbitrary file deletion vulnerability via the component /accessory/picdel.html.
ModificadaMedia (5.4)0.47%—Teacms Project Teacms24/3/202317/6/2026
A vulnerability was found in XiaoBingBy TeaCMS up to 2.0.2. It has been classified as problematic. Affected is an unknown function of the component Article Title Handler. The manipulation with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to launch the attack remotely.…
ModificadaCrítica (9.8)1.3%—Lightcms Project Lightcms22/3/202317/6/2026
LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.
ModificadaCrítica (9.8)0.79%—Xzjie CMS Project Xzjie CMS18/3/202317/6/2026
A vulnerability was found in xzjie cms up to 1.0.3 and classified as critical. This issue affects some unknown processing of the file /api/upload. The manipulation of the argument uploadFile leads to unrestricted upload. The attack may be initiated remotely. The associated identifier of this vulnerability is…
ModificadaCrítica (9.8)0.62%—Teacms Project Teacms18/3/202317/6/2026
A vulnerability has been found in XiaoBingBy TeaCMS up to 2.0.2 and classified as critical. This vulnerability affects unknown code of the file /admin/getallarticleinfo. The manipulation of the argument searchInfo leads to sql injection. The attack can be initiated remotely. VDB-223366 is the identifier assigned to…
ModificadaAlta (8.8)0.77%—Hkcms Project Hkcms18/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. This affects an unknown part of the file /admin.php/appcenter/local.html?type=addon of the component External Plugin Handler. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has…
ModificadaAlta (8.8)0.84%—Ofcms Project Ofcms16/3/202317/6/2026
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.
ModificadaAlta (8.8)0.97%—Teacms Project Teacms14/3/202317/6/2026
A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/upload. The manipulation leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaCrítica (9.8)0.80%—Xhcms Project Xhcms13/3/202317/6/2026
A vulnerability was found in XHCMS 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php of the component POST Parameter Handler. The manipulation of the argument user leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaCrítica (9.8)0.79%—Ucms Project Ucms9/3/202317/6/2026
A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadmin/fileedit.php of the component System File Management Module. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The associated…
ModificadaCrítica (9.8)0.74%—Lionfish CMS Project Lionfish CMS2/3/202317/6/2026
A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function goods_detail of the file ApiController.class.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and…
ModificadaAlta (7.2)0.93%—Balero CMS Project Balero CMS24/2/202317/6/2026
File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /admin/main/mod-blog page.
ModificadaMedia (6.5)0.32%—Baijiacms Project Baijiacms15/2/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via index.php.
ModificadaMedia (5.4)0.51%—Tpcms Project Tpcms3/2/202317/6/2026
Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyright or cfg_tel field in Site Configuration page.
ModificadaAlta (7.5)0.92%—Tpcms Project Tpcms3/2/202317/6/2026
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.
ModificadaAlta (8.1)0.79%—Portfoliocms Project Portfoliocms3/2/202317/6/2026
Race condition vulnerability discovered in portfolioCMS 1.0 allows remote attackers to run arbitrary code via fileExt parameter to localhost/admin/uploads.php.
Orbitaley — Vulnerabilidades