Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.53% | — | Sem-cms Semcms | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter. | |
| Modificada | Alta (8.8) | 0.57% | — | Mingsoft Mcms | 23/9/2018 | 17/6/2026 | An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. | |
| Modificada | Media (4.8) | 0.51% | — | Yzmcms | 14/9/2018 | 17/6/2026 | In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Seamcms Seacms | 4/9/2018 | 17/6/2026 | An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt. | |
| Modificada | Media (4.8) | 0.56% | — | Chemcms Project Chemcms | 2/9/2018 | 17/6/2026 | ChemCMS 1.0.6 has XSS via the "setting -> website information" field. | |
| Modificada | Crítica (9.8) | 1.6% | — | Golemcms Project Golemcms | 24/7/2018 | 17/6/2026 | GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by inserting this code into the "Database Information" "Table prefix" form field, or obtain sensitive information via a direct request for install/install.sql. | |
| Modificada | Crítica (9.8) | 1.6% | — | Nmark Nmcms | 21/6/2018 | 17/6/2026 | NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI. | |
| Modificada | Crítica (9.8) | 1.4% | — | Yzmcms | 5/6/2018 | 17/6/2026 | The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts via a brute-force approach. | |
| Modificada | Alta (8.8) | 0.51% | — | Chemcms Project Chemcms | 22/4/2018 | 17/6/2026 | ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account. | |
| Modificada | Media (6.8) | 0.48% | — | Yzmcms | 19/4/2018 | 17/6/2026 | An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html. | |
| Modificada | Media (6.8) | 0.48% | — | Yzmcms | 19/4/2018 | 17/6/2026 | An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html. | |
| Modificada | Media (4.8) | 0.52% | — | Yzmcms | 11/4/2018 | 17/6/2026 | The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php. | |
| Modificada | Alta (7.2) | 3.3% | — | Yzmcms | 18/3/2018 | 17/6/2026 | Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in the POST data of an index.php?m=member&c=member_content&a=init request. | |
| Modificada | Media (5.4) | 0.80% | 💥 PoC | Yzmcms | 13/3/2018 | 17/6/2026 | YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html. | |
| Modificada | Media (6.1) | 7.9% | 💥 Exploit | Yzmcms | 4/3/2018 | 17/6/2026 | In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter. | |
| Modificada | Alta (7.2) | 0.97% | — | Yzmcms | 1/3/2018 | 17/6/2026 | \application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html. | |
| Modificada | Media (5.3) | 2.0% | — | Yzmcms | 26/2/2018 | 17/6/2026 | YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Thedigitalcraft Atomcms | 10/7/2014 | 17/6/2026 | SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Slimcms | 24/12/2008 | 16/6/2026 | redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Slimcms | 12/12/2008 | 16/6/2026 | SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter. | |
| Modificada | Alta (10) | 3.5% | 💥 Exploit | Customcms Ccms | 9/10/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php, (2) forums.php, (3) admin.php, (4) header.php, (5) pages/story.php and (6) pages/poll.php. | |
| Modificada | Media (6.8) | 0.94% | 💥 Exploit | Customcms Gaming Portal | 19/9/2008 | 16/6/2026 | SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Deeemm Dmcms | 20/8/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Deeemm Dmcms | 20/8/2008 | 16/6/2026 | SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the id vector is already covered by CVE-2007-5679. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Customcms Ccms | 4/1/2008 | 16/6/2026 | SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page. |