Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

824 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)1.2%💥 ExploitDedecms11/2/202517/6/2026
Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.
AplazadaMedia (5.3)0.32%—MaybecmsAI30/1/202517/6/2026
A vulnerability classified as problematic has been found in Maybecms 1.2. This affects an unknown part of the file /mb/admin/index.php?u=article-edit of the component Add Article. The manipulation of the argument data_info[content] leads to cross site scripting. It is possible to initiate the attack remotely. The…
AnalizadaAlta (7.5)0.50%—Thecosy Icecms14/1/202517/6/2026
An access control issue in the component /api/squareComment/DelectSquareById of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.
AnalizadaAlta (7.5)0.50%—Thecosy Icecms14/1/202517/6/2026
An access control issue in the component /square/getAllSquare/circle of iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information.
AnalizadaMedia (5.3)0.44%—Dedecms4/12/202417/6/2026
A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP POST Request Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.41%—Dedecms4/12/202417/6/2026
A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some unknown functionality of the file /member/soft_add.php. The manipulation of the argument body leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.3)0.41%—Dedecms4/12/202417/6/2026
A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component SWF File Handler. The manipulation of the argument mediatype leads to cross site scripting. The attack can be launched remotely. The…
AnalizadaMedia (5.3)0.45%—Dedecms4/12/202417/6/2026
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file /member/article_add.php. The manipulation of the argument body leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (5.1)2.6%—Dedecms12/11/202417/6/2026
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (6.9)0.38%—Get-simple Getsimplecms12/11/202417/6/2026
A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor…
AnalizadaCrítica (9.8)0.64%—Thecosy Icecms30/10/202417/6/2026
icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.
AplazadaMedia (6.3)0.40%—QilecmsAI13/10/202417/6/2026
A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function sendEmail of the file /qilecms/user/controller/Forget.php of the component Verification Code Handler. The manipulation leads to weak password recovery. The attack can be initiated remotely. The…
AnalizadaMedia (4.9)0.34%—Bluecms Project Bluecms7/10/202417/6/2026
BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.
ModificadaMedia (5.1)0.53%—Concretecms Concrete CMS25/9/202417/6/2026
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color. A rogue admin could add malicious code to the Thumbnails/Add-Type. The Concrete CMS Security Team gave this a CVSS v4 score of 5.1 with vector…
ModificadaMedia (4.6)0.49%—Concretecms Concrete CMS25/9/202417/6/2026
Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addition feature because the calendar event name was not sanitized on output. Users or groups with permission to create event calendars can embed scripts, and users or groups with permission to modify…
AnalizadaCrítica (9.8)0.63%—Thecosy Icecms25/9/202417/6/2026
IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.
ModificadaAlta (7.5)0.47%—Thecosy Icecms25/9/202417/6/2026
An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java
AnalizadaAlta (7.5)0.67%—Thecosy Icecms25/9/202417/6/2026
An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords
ModificadaAlta (7.6)0.52%—Thecosy Icecms25/9/20245/7/2026
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
ModificadaMedia (5.1)21%—Dedecms22/9/202417/6/2026
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The…
AnalizadaAlta (8.8)0.52%—Dedecms18/9/202417/6/2026
Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
ModificadaMedia (6.1)0.28%—Dedecms18/9/202417/6/2026
DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.
AnalizadaMedia (4.6)0.29%—Concretecms Concrete CMS17/9/202417/6/2026
Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output was not sufficiently sanitized, a rogue administrator could add a malicious payload that could be executed when targeted users visited the home page.The Concrete…
AnalizadaMedia (4.6)0.44%—Concretecms Concrete CMS16/9/202417/6/2026
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A rogue administrator could add a malicious payload by executing it in the browsers of targeted users. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 with vector…
AnalizadaMedia (5.3)0.78%—Xiaohe4966 Tpmecms15/9/202417/6/2026
A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by this issue is some unknown functionality of the file /index/ajax/lang. The manipulation of the argument lang leads to path traversal. The attack may be launched remotely. The exploit has been disclosed…