Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Wuzhicms20/9/202117/6/2026
An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.
ModificadaCrítica (9.8)1.3%—Wuzhicms16/9/202117/6/2026
SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/card.php file.
ModificadaCrítica (9.8)1.3%—Wuzhicms16/9/202117/6/2026
SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/index.php file.
ModificadaAlta (7.2)1.7%—Jizhicms15/9/202117/6/2026
An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to a PHP file.
ModificadaCrítica (9.8)1.8%—Feehicms15/9/202117/6/2026
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (6.1)0.64%—Feehicms26/8/202117/6/2026
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
ModificadaMedia (4.3)0.36%—Popojicms25/8/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability exist in PopojiCMS 2.0.1 in po-admin/route.php?mod=user&act=multidelete.
ModificadaMedia (6.5)1.2%—Popojicms25/8/202117/6/2026
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
ModificadaMedia (5.4)0.52%—Popojicms25/8/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
ModificadaAlta (7.5)1.5%—Wuzhicms20/8/202117/6/2026
SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'.
ModificadaAlta (8)0.46%—Damicms12/8/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
ModificadaMedia (4.8)0.53%—Damicms12/8/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in DamiCMS v6.0.6 via the title parameter in the doadd function in LabelAction.class.php.
ModificadaMedia (6.1)0.78%—Popojicms6/8/202117/6/2026
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field.
ModificadaMedia (5.3)0.90%—Popojicms6/8/202117/6/2026
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
ModificadaMedia (6.1)1.5%—Wuzhicms22/6/202117/6/2026
Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".
ModificadaAlta (8.8)0.52%—Idreamsoft Icms28/5/202117/6/2026
A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.
ModificadaCrítica (9.1)2.2%—Idreamsoft Icms30/4/202117/6/2026
Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php".
ModificadaMedia (6.1)1.6%—1234n Minicms28/4/202117/6/2026
Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".
ModificadaCrítica (9.1)2.6%—Feifeicms22/4/202117/6/2026
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component.
ModificadaCrítica (9.1)2.6%—Feifeicms22/4/202117/6/2026
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to " /index.php?s=/admin-tpl-del&id=".
ModificadaMedia (4.3)1.3%—Wuzhicms2/4/202117/6/2026
Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.
ModificadaMedia (6.1)0.70%—Jizhicms11/1/202117/6/2026
XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.
ModificadaMedia (6.1)0.70%—Jizhicms11/1/202117/6/2026
XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.
ModificadaCrítica (9.8)1.9%—1234n Minicms5/1/202117/6/2026
Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.
ModificadaAlta (7.5)2.0%—1234n Minicms5/1/202117/6/2026
Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.
Orbitaley — Vulnerabilidades