Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
663 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.85% | — | Native-php-cms Project Native-php-cms | 3/2/2023 | 17/6/2026 | SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php file. | |
| Modificada | Crítica (9.1) | 0.86% | — | Jocms Project Jocms | 3/2/2023 | 17/6/2026 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php. | |
| Modificada | Crítica (9.1) | 0.86% | — | Jocms Project Jocms | 3/2/2023 | 17/6/2026 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php. | |
| Modificada | Alta (7.5) | 0.85% | — | Jocms Project Jocms | 3/2/2023 | 17/6/2026 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_set_mask() function in jocms/apps/mask/mask.php. | |
| Modificada | Crítica (9.1) | 0.86% | — | Jocms Project Jocms | 3/2/2023 | 17/6/2026 | SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php. | |
| Modificada | Media (5.3) | 0.76% | — | Fastcms Project Fastcms | 2/2/2023 | 17/6/2026 | A vulnerability was found in FastCMS 0.1.0. It has been classified as critical. Affected is an unknown function of the component Template Management. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Alta (7.5) | 0.75% | — | Portfoliocms Project Portfoliocms | 31/1/2023 | 17/6/2026 | Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation. | |
| Modificada | Alta (7.2) | 1.4% | — | Ayacms Project Ayacms | 27/1/2023 | 17/6/2026 | AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php. | |
| Modificada | Media (6.1) | 0.50% | — | Mycms Project Mycms | 19/1/2023 | 17/6/2026 | A vulnerability was found in MyCMS. It has been classified as problematic. This affects the function build_view of the file lib/gener/view.php of the component Visitors Module. The manipulation of the argument original/converted leads to cross site scripting. It is possible to initiate the attack remotely. The patch… | |
| Modificada | Crítica (9.8) | 0.78% | — | Tuzicms Project Tuzicms | 12/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in TuziCMS 2.0.6. This vulnerability affects the function delall of the file \App\Manage\Controller\KefuController.class.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.73% | — | Tuzicms Project Tuzicms | 12/1/2023 | 17/6/2026 | A vulnerability classified as critical has been found in TuziCMS 2.0.6. This affects the function index of the file App\Manage\Controller\ArticleController.class.php of the component Article Module. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Modificada | Crítica (9.8) | 0.80% | — | Ayacms Project Ayacms | 22/12/2022 | 17/6/2026 | AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php | |
| Modificada | Crítica (9.8) | 0.74% | — | Ayacms Project Ayacms | 22/12/2022 | 17/6/2026 | AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php | |
| Modificada | Alta (8.8) | 1.1% | — | Ayacms Project Ayacms | 22/12/2022 | 17/6/2026 | AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code. | |
| Modificada | Crítica (9.8) | 0.74% | — | Classcms Project Classcms | 22/12/2022 | 17/6/2026 | here is an arbitrary file upload vulnerability in the file management function module of Classcms3.5. | |
| Modificada | Media (6.1) | 0.36% | — | Imprint CMS Project Imprint CMS | 21/12/2022 | 17/6/2026 | A vulnerability was found in Imprint CMS. It has been classified as problematic. Affected is the function SearchForm of the file ImprintCMS/Models/ViewHelpers.cs. The manipulation of the argument query leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is… | |
| Modificada | Alta (8.8) | 22% | — | Baijiacms Project Baijiacms | 20/12/2022 | 17/6/2026 | A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4. | |
| Modificada | Alta (7.5) | 1.4% | — | Aerocms Project Aerocms | 16/12/2022 | 17/6/2026 | AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1. | |
| Modificada | Alta (7.2) | 1.2% | — | Aerocms Project Aerocms | 16/12/2022 | 17/6/2026 | In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server. | |
| Modificada | Alta (7.2) | 0.86% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks. | |
| Modificada | Media (6.5) | 0.33% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Media (6.1) | 0.47% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | AeroCMS v0.0.1 is vulnerable to ClickJacking. | |
| Modificada | Media (4.8) | 0.46% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field. | |
| Modificada | Media (4.9) | 0.76% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter. | |
| Modificada | Crítica (9.6) | 0.55% | — | Pb-cms Project Pb-cms | 8/12/2022 | 17/6/2026 | A vulnerability was found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /blog/comment of the component Message Board. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… |