Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.53%—Sem-cms Semcms29/10/201817/6/2026
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.
ModificadaAlta (8.8)0.57%—Mingsoft Mcms23/9/201817/6/2026
An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
ModificadaMedia (4.8)0.51%—Yzmcms14/9/201817/6/2026
In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
ModificadaAlta (7.5)1.9%—Seamcms Seacms4/9/201817/6/2026
An issue was discovered in SeaCMS through 6.61. adm1n/admin_database.php allows remote attackers to delete arbitrary files via directory traversal sequences in the bakfiles parameter. This can allow the product to be reinstalled by deleting install_lock.txt.
ModificadaMedia (4.8)0.56%—Chemcms Project Chemcms2/9/201817/6/2026
ChemCMS 1.0.6 has XSS via the "setting -> website information" field.
ModificadaCrítica (9.8)1.6%—Golemcms Project Golemcms24/7/201817/6/2026
GolemCMS through 2008-12-24, if the install/ directory remains active after an installation, allows remote attackers to execute arbitrary PHP code by inserting this code into the "Database Information" "Table prefix" form field, or obtain sensitive information via a direct request for install/install.sql.
ModificadaCrítica (9.8)1.6%—Nmark Nmcms21/6/201817/6/2026
NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.
ModificadaCrítica (9.8)1.4%—Yzmcms5/6/201817/6/2026
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a verification code, which makes it easier for remote attackers to hijack accounts via a brute-force approach.
ModificadaAlta (8.8)0.51%—Chemcms Project Chemcms22/4/201817/6/2026
ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account.
ModificadaMedia (6.8)0.48%—Yzmcms19/4/201817/6/2026
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.
ModificadaMedia (6.8)0.48%—Yzmcms19/4/201817/6/2026
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.
ModificadaMedia (4.8)0.52%—Yzmcms11/4/201817/6/2026
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
ModificadaAlta (7.2)3.3%—Yzmcms18/3/201817/6/2026
Eval injection in yzmphp/core/function/global.func.php in YzmCMS v3.7.1 allows remote attackers to achieve arbitrary code execution via PHP code in the POST data of an index.php?m=member&c=member_content&a=init request.
ModificadaMedia (5.4)0.80%💥 PoCYzmcms13/3/201817/6/2026
YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html.
ModificadaMedia (6.1)7.9%💥 ExploitYzmcms4/3/201817/6/2026
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
ModificadaAlta (7.2)0.97%—Yzmcms1/3/201817/6/2026
\application\admin\controller\update_urls.class.php in YzmCMS 3.6 has SQL Injection via the catids array parameter to admin/update_urls/update_category_url.html.
ModificadaMedia (5.3)2.0%—Yzmcms26/2/201817/6/2026
YzmCMS 3.6 allows remote attackers to discover the full path via a direct request to application/install/templates/s1.php.
ModificadaAlta (7.5)2.2%💥 ExploitThedigitalcraft Atomcms10/7/201417/6/2026
SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)2.6%💥 ExploitSlimcms24/12/200816/6/2026
redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.
ModificadaAlta (7.5)0.97%💥 ExploitSlimcms12/12/200816/6/2026
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter.
ModificadaAlta (10)3.5%💥 ExploitCustomcms Ccms9/10/200816/6/2026
Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php, (2) forums.php, (3) admin.php, (4) header.php, (5) pages/story.php and (6) pages/poll.php.
ModificadaMedia (6.8)0.94%💥 ExploitCustomcms Gaming Portal19/9/200816/6/2026
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (7.5)2.5%💥 ExploitDeeemm Dmcms20/8/200816/6/2026
PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.
ModificadaAlta (7.5)1.0%💥 ExploitDeeemm Dmcms20/8/200816/6/2026
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the id vector is already covered by CVE-2007-5679.
ModificadaAlta (7.5)1.2%💥 ExploitCustomcms Ccms4/1/200816/6/2026
SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page.