Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.1% | — | Wuzhicms | 20/9/2021 | 17/6/2026 | An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php. | |
| Modificada | Crítica (9.8) | 1.3% | — | Wuzhicms | 16/9/2021 | 17/6/2026 | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file. | |
| Modificada | Crítica (9.8) | 1.3% | — | Wuzhicms | 16/9/2021 | 17/6/2026 | SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file. | |
| Modificada | Alta (7.2) | 1.7% | — | Jizhicms | 15/9/2021 | 17/6/2026 | An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to a PHP file. | |
| Modificada | Crítica (9.8) | 1.8% | — | Feehicms | 15/9/2021 | 17/6/2026 | An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (6.1) | 0.64% | — | Feehicms | 26/8/2021 | 17/6/2026 | Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload. | |
| Modificada | Media (4.3) | 0.36% | — | Popojicms | 25/8/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete. | |
| Modificada | Media (6.5) | 1.2% | — | Popojicms | 25/8/2021 | 17/6/2026 | Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php. | |
| Modificada | Media (5.4) | 0.52% | — | Popojicms | 25/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu. | |
| Modificada | Alta (7.5) | 1.5% | — | Wuzhicms | 20/8/2021 | 17/6/2026 | SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'. | |
| Modificada | Alta (8) | 0.46% | — | Damicms | 12/8/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd. | |
| Modificada | Media (4.8) | 0.53% | — | Damicms | 12/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php. | |
| Modificada | Media (6.1) | 0.78% | — | Popojicms | 6/8/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field. | |
| Modificada | Media (5.3) | 0.90% | — | Popojicms | 6/8/2021 | 17/6/2026 | An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads. | |
| Modificada | Media (6.1) | 1.5% | — | Wuzhicms | 22/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php". | |
| Modificada | Alta (8.8) | 0.52% | — | Idreamsoft Icms | 28/5/2021 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts. | |
| Modificada | Crítica (9.1) | 2.2% | — | Idreamsoft Icms | 30/4/2021 | 17/6/2026 | Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php". | |
| Modificada | Media (6.1) | 1.6% | — | 1234n Minicms | 28/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php". | |
| Modificada | Crítica (9.1) | 2.6% | — | Feifeicms | 22/4/2021 | 17/6/2026 | Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component. | |
| Modificada | Crítica (9.1) | 2.6% | — | Feifeicms | 22/4/2021 | 17/6/2026 | Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to " /index.php?s=/admin-tpl-del&id=". | |
| Modificada | Media (4.3) | 1.3% | — | Wuzhicms | 2/4/2021 | 17/6/2026 | Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter. | |
| Modificada | Media (6.1) | 0.70% | — | Jizhicms | 11/1/2021 | 17/6/2026 | XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php. | |
| Modificada | Media (6.1) | 0.70% | — | Jizhicms | 11/1/2021 | 17/6/2026 | XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | 1234n Minicms | 5/1/2021 | 17/6/2026 | Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | 1234n Minicms | 5/1/2021 | 17/6/2026 | Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter. |