Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
824 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 1.2% | 💥 Exploit | Dedecms | 11/2/2025 | 17/6/2026 | Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection. | |
| Aplazada | Media (5.3) | 0.32% | — | MaybecmsAI | 30/1/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/admin/index.php?u=article-edit of the component Add Article. The manipulation of the argument data_info[content] leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analizada | Alta (7.5) | 0.50% | — | Thecosy Icecms | 14/1/2025 | 17/6/2026 | An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information. | |
| Analizada | Alta (7.5) | 0.50% | — | Thecosy Icecms | 14/1/2025 | 17/6/2026 | An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information. | |
| Analizada | Media (5.3) | 0.44% | — | Dedecms | 4/12/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP POST Request Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.41% | — | Dedecms | 4/12/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some unknown functionality of the file /member/soft_add.php. The manipulation of the argument body leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.41% | — | Dedecms | 4/12/2024 | 17/6/2026 | A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component SWF File Handler. The manipulation of the argument mediatype leads to cross site scripting. The attack can be launched remotely. The… | |
| Analizada | Media (5.3) | 0.45% | — | Dedecms | 4/12/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file /member/article_add.php. The manipulation of the argument body leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.1) | 2.6% | — | Dedecms | 12/11/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.38% | — | Get-simple Getsimplecms | 12/11/2024 | 17/6/2026 | A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor… | |
| Analizada | Crítica (9.8) | 0.64% | — | Thecosy Icecms | 30/10/2024 | 17/6/2026 | icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile. | |
| Aplazada | Media (6.3) | 0.40% | — | QilecmsAI | 13/10/2024 | 17/6/2026 | A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component Verification Code Handler. The manipulation leads to weak password recovery. The attack can be initiated remotely. The… | |
| Analizada | Media (4.9) | 0.34% | — | Bluecms Project Bluecms | 7/10/2024 | 17/6/2026 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request. | |
| Modificada | Media (5.1) | 0.53% | — | Concretecms Concrete CMS | 25/9/2024 | 17/6/2026 | Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete CMS Security Team gave this a CVSS v4 score of 5.1 with vector… | |
| Modificada | Media (4.6) | 0.49% | — | Concretecms Concrete CMS | 25/9/2024 | 17/6/2026 | Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output. Users or groups with permission to create event calendars can embed scripts, and users or groups with permission to modify… | |
| Analizada | Crítica (9.8) | 0.63% | — | Thecosy Icecms | 25/9/2024 | 17/6/2026 | IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information. | |
| Modificada | Alta (7.5) | 0.47% | — | Thecosy Icecms | 25/9/2024 | 17/6/2026 | An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java | |
| Analizada | Alta (7.5) | 0.67% | — | Thecosy Icecms | 25/9/2024 | 17/6/2026 | An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords | |
| Modificada | Alta (7.6) | 0.52% | — | Thecosy Icecms | 25/9/2024 | 5/7/2026 | Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file. | |
| Modificada | Media (5.1) | 21% | — | Dedecms | 22/9/2024 | 17/6/2026 | A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Alta (8.8) | 0.52% | — | Dedecms | 18/9/2024 | 17/6/2026 | Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend. | |
| Modificada | Media (6.1) | 0.28% | — | Dedecms | 18/9/2024 | 17/6/2026 | DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module. | |
| Analizada | Media (4.6) | 0.29% | — | Concretecms Concrete CMS | 17/9/2024 | 17/6/2026 | Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page.The Concrete… | |
| Analizada | Media (4.6) | 0.44% | — | Concretecms Concrete CMS | 16/9/2024 | 17/6/2026 | Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A rogue administrator could add a malicious payload by executing it in the browsers of targeted users. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 with vector… | |
| Analizada | Media (5.3) | 0.78% | — | Xiaohe4966 Tpmecms | 15/9/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed… |