Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.8%—Craftcms Craft CMS24/10/201917/6/2026
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
ModificadaMedia (6.1)0.84%—Craftcms Craft CMS11/10/201917/6/2026
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
ModificadaMedia (5.3)9.4%💥 ExploitCraftcms Craft CMS26/7/201917/6/2026
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
ModificadaMedia (6.1)0.94%—Craftcms Craft CMS18/6/201917/6/2026
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
ModificadaAlta (7.2)1.5%—Craftcms Craft CMS25/12/201817/6/2026
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be…
ModificadaMedia (4.8)3.7%💥 ExploitCraftcms Craft CMS24/12/201817/6/2026
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
ModificadaAlta (8.8)1.9%—Craftcms Craft CMS1/1/201817/6/2026
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension.
ModificadaMedia (5.4)2.8%💥 ExploitCraftcms Craft CMS8/6/201717/6/2026
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
ModificadaMedia (5.3)0.96%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
ModificadaMedia (6.1)0.84%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
ModificadaMedia (5.3)1.2%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
ModificadaMedia (6.1)0.83%—Craftcms Craft CMS22/4/201717/6/2026
Craft CMS before 2.6.2974 allows XSS attacks.