Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.63%—Craftcms Craft CMS3/4/202217/6/2026
Craft CMS before 3.7.29 allows XSS.
ModificadaAlta (8.8)1.4%—Craftcms Craft CMS30/9/202117/6/2026
Craft CMS before 3.7.14 allows CSV injection.
ModificadaCrítica (9.8)2.8%—Craftcms Craft CMS30/6/202117/6/2026
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
ModificadaMedia (6.1)0.99%—Craftcms Craft CMS30/6/202117/6/2026
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
ModificadaMedia (6.1)0.73%—Craftcms Craft CMS7/5/202117/6/2026
Craft CMS before 3.6.13 has an XSS vulnerability.
ModificadaMedia (5.4)0.85%—Craftcms Craft CMS26/3/202117/6/2026
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
ModificadaCrítica (9.8)73%💥 ExploitCraftcms Craft CMS4/3/202017/6/2026
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
ModificadaMedia (6.1)3.7%💥 ExploitCraftcms Craft CMS31/12/201917/6/2026
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
ModificadaCrítica (9.8)1.8%—Craftcms Craft CMS24/10/201917/6/2026
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
ModificadaMedia (6.1)0.84%—Craftcms Craft CMS11/10/201917/6/2026
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
ModificadaMedia (5.3)9.4%💥 ExploitCraftcms Craft CMS26/7/201917/6/2026
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
ModificadaMedia (6.1)0.94%—Craftcms Craft CMS18/6/201917/6/2026
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
ModificadaAlta (8.8)2.8%—Moxa Softcms21/3/201917/6/2026
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
ModificadaAlta (8.8)2.8%—Moxa Softcms21/3/201917/6/2026
Moxa SoftCMS 1.3 and prior is susceptible to a buffer overflow condition that may crash or allow remote code execution. Moxa released SoftCMS version 1.4 on June 1, 2015, to address the vulnerability.
ModificadaAlta (7.2)1.5%—Craftcms Craft CMS25/12/201817/6/2026
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be…
ModificadaMedia (4.8)3.7%💥 ExploitCraftcms Craft CMS24/12/201817/6/2026
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
ModificadaCrítica (9.8)1.2%—Moxa Softcms LAB View18/1/201817/6/2026
A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified. Attackers can exploit this vulnerability to access SoftCMS without knowing the user's password.
ModificadaAlta (8.8)1.9%—Craftcms Craft CMS1/1/201817/6/2026
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension.
ModificadaMedia (5.4)2.8%💥 ExploitCraftcms Craft CMS8/6/201717/6/2026
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
ModificadaMedia (5.3)0.96%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
ModificadaMedia (6.1)0.84%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
ModificadaMedia (5.3)1.2%—Craftcms Craft CMS1/5/201717/6/2026
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
ModificadaMedia (6.1)0.83%—Craftcms Craft CMS22/4/201717/6/2026
Craft CMS before 2.6.2974 allows XSS attacks.
ModificadaCrítica (9.8)1.9%—Moxa Softcms13/2/201717/6/2026
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTION).
ModificadaAlta (7.5)8.2%💥 ExploitMoxa Softcms13/2/201717/6/2026
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could provide unexpected values and cause the program to crash or excessive consumption of resources could result in a denial-of-service condition.
Orbitaley — Vulnerabilidades