Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Xcms | 4/1/2008 | 16/6/2026 | cpie.php in XCMS 1.83 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct direct static code injection attacks and execute arbitrary code via the testo_0 parameter in a cpie admin action to index.php, which writes to dati/generali/footer.dtb (aka the XCMS footer). | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Xcms | 31/12/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in index.php in XCMS 1.82 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the s parameter to the admin page or (2) the pg parameter to an arbitrary module, as demonstrated by reading a password hash in a .dtb file under dati/membri/ or… | |
| Modificada | Media (6.8) | 0.99% | — | Modxcms | 11/10/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in mutate_content.dynamic.php in MODx 0.9.6 allow remote attackers to execute arbitrary SQL commands via the (1) documentDirty or (2) modVariables parameter. | |
| Modificada | Media (4.3) | 0.88% | 💥 Exploit | Xcms | 24/9/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the cpass functionality in an admin action in index.php in XCMS allows remote attackers to change arbitrary passwords via certain password_ and rpassword_ parameters, possibly related to timestamp values. | |
| Modificada | Media (6.4) | 2.4% | 💥 Exploit | Groupeclan.free.fr Xcms | 3/7/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) Ent or (2) Lang parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Bloofoxcms | 26/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in plugins/spaw/img_popup.php in BloofoxCMS 0.2.2 allows remote attackers to inject arbitrary web script or HTML via the img_url parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Bloofoxcms | 26/4/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in install/index.php in BlooFoxCMS 0.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the content_php parameter. NOTE: this issue has been disputed by a reliable third party, stating that content_php is initialized before use | |
| Modificada | Alta (7.5) | 1.5% | — | Modxcms Filedownload | 1/2/2007 | 16/6/2026 | download.php in the MuddyDogPaws FileDownload snippet before 2.5 for MODx allows remote attackers to download arbitrary files, as demonstrated by downloading config.inc.php to obtain database credentials. | |
| Modificada | Media (5.1) | 3.0% | 💥 Exploit | Modxcms | 6/11/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. NOTE: it is possible that this is a vulnerability in FCKeditor. | |
| Modificada | Alta (7.5) | 1.5% | — | Forum ONE Syntaxcms | 3/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SyntaxCMS 1.1.1 through 1.3 allow remote attackers to execute arbitrary PHP code via a URL in (1) the init_path parameter to admin/testing/tests/0030_init_syntax.php, or (2) an unspecified parameter to admin/testing/index.php. NOTE: the 0004_init_urls.php vector is… | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Forum ONE Syntaxcms | 28/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the init_path parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Cavoxcms | 22/6/2006 | 16/6/2026 | SQL injection vulnerability in index.php in CavoxCms 1.0.16 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (5.1) | 2.8% | 💥 Exploit | SIX Offene Systeme Gmbh Sixcms | 16/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary script code or HTML via the page parameter. | |
| Modificada | Baja (2.6) | 3.1% | 💥 Exploit | SIX Offene Systeme Gmbh Sixcms | 16/6/2006 | 16/6/2026 | Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter. | |
| Modificada | Media (6.4) | 3.0% | 💥 Exploit | Modxcms | 18/4/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter. | |
| Modificada | Media (5.8) | 2.1% | 💥 Exploit | Modxcms | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Forum ONE Syntaxcms | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search in SyntaxCMS 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. |