Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Zzcms | 5/4/2018 | 17/6/2026 | An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request. | |
| Modificada | Alta (7.5) | 2.6% | — | Zzcms | 24/3/2018 | 17/6/2026 | An issue was discovered in zzcms 8.2. user/licence_save.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | |
| Modificada | Alta (7.5) | 2.6% | — | Zzcms | 24/3/2018 | 17/6/2026 | An issue was discovered in zzcms 8.2. user/manage.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg or oldflv parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | |
| Modificada | Crítica (9.8) | 1.8% | — | Zzcms | 24/3/2018 | 17/6/2026 | An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in an adv2.php?action=modify request. | |
| Modificada | Alta (7.5) | 1.8% | — | Zzcms | 24/3/2018 | 17/6/2026 | An issue was discovered in zzcms 8.2. It allows PHP code injection via the siteurl parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php. | |
| Modificada | Alta (7.5) | 2.6% | — | Zzcms | 24/3/2018 | 17/6/2026 | An issue was discovered in zzcms 8.2. user/ppsave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can be leveraged for database access by deleting install.lock. | |
| Modificada | Media (5.3) | 2.3% | — | Zzcms | 24/2/2018 | 17/6/2026 | zzcms 8.2 allows remote attackers to discover the full path via a direct request to 3/qq_connect2.0/API/class/ErrorCase.class.php or 3/ucenter_api/code/friend.php. | |
| Modificada | Media (4.8) | 1.1% | 💥 Exploit | Zcms Project Zcms | 20/9/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1. | |
| Modificada | Crítica (9.8) | 3.7% | 💥 Exploit | Zcms Project Zcms | 7/6/2017 | 17/6/2026 | SQL injection vulnerability in ZCMS 1.1. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Eztechhelp Ezcms | 30/6/2008 | 16/6/2026 | admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Eztechhelp Company Ezcms | 30/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. |