Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

329 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Idreamsoft Icms10/12/202017/6/2026
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
ModificadaCrítica (9.8)1.6%—Idreamsoft Icms10/12/202017/6/2026
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
ModificadaMedia (6.5)0.40%—Idreamsoft Icms10/9/202017/6/2026
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.
ModificadaMedia (6.1)1.2%💥 ExploitUlicms7/5/202017/6/2026
UliCMS before 2020.2 has PageController stored XSS.
ModificadaMedia (6.1)0.64%—Ulicms7/5/202017/6/2026
UliCMS before 2020.2 has XSS during PackageController uninstall.
ModificadaMedia (6.1)0.81%—Popojicms7/11/201917/6/2026
po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS.
ModificadaMedia (6.1)0.71%—Popojicms7/11/201917/6/2026
PopojiCMS 2.0.1 allows refer= Open Redirection.
ModificadaAlta (8.8)0.47%—Jizhicms14/10/201917/6/2026
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
ModificadaAlta (7.5)1.3%—Idreamsoft Icms14/10/201917/6/2026
idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer.
ModificadaCrítica (9.8)1.1%—Idreamsoft Icms14/10/201917/6/2026
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
ModificadaMedia (5.4)0.61%—Xunruicms1/10/201917/6/2026
An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area.
ModificadaMedia (6.5)0.47%—Idreamsoft Icms21/9/201917/6/2026
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
ModificadaAlta (8.8)0.55%—Tuzicms21/9/201917/6/2026
TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF.
ModificadaAlta (8.8)0.55%—Tuzicms21/9/201917/6/2026
TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF.
ModificadaMedia (6.1)0.75%—Tuzicms21/9/201917/6/2026
TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.
ModificadaCrítica (9.8)1.4%—Tuzicms20/9/201917/6/2026
App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring.
ModificadaCrítica (9.8)1.7%—Yejiao Tuzicms20/9/201917/6/2026
App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring.
ModificadaMedia (6.1)0.83%—Icmsdev Icms12/8/201917/6/2026
iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter.
ModificadaMedia (4.9)1.6%—Damicms10/7/201917/6/2026
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
ModificadaMedia (4.8)0.62%—1234n Minicms5/7/201917/6/2026
In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie.
ModificadaMedia (4.8)0.62%—1234n Minicms5/7/201917/6/2026
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.
ModificadaMedia (4.8)0.63%—1234n Minicms5/7/201917/6/2026
In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie.
ModificadaMedia (6.1)0.86%—1234n Minicms3/7/201917/6/2026
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520.
ModificadaMedia (6.1)3.5%💥 ExploitUlicms8/5/201917/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon.
ModificadaMedia (6.1)0.83%—Idreamsoft Icms22/4/201917/6/2026
An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter.