Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
329 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.6% | — | Idreamsoft Icms | 10/12/2020 | 17/6/2026 | iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Idreamsoft Icms | 10/12/2020 | 17/6/2026 | iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php. | |
| Modificada | Media (6.5) | 0.40% | — | Idreamsoft Icms | 10/9/2020 | 17/6/2026 | A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Ulicms | 7/5/2020 | 17/6/2026 | UliCMS before 2020.2 has PageController stored XSS. | |
| Modificada | Media (6.1) | 0.64% | — | Ulicms | 7/5/2020 | 17/6/2026 | UliCMS before 2020.2 has XSS during PackageController uninstall. | |
| Modificada | Media (6.1) | 0.81% | — | Popojicms | 7/11/2019 | 17/6/2026 | po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS. | |
| Modificada | Media (6.1) | 0.71% | — | Popojicms | 7/11/2019 | 17/6/2026 | PopojiCMS 2.0.1 allows refer= Open Redirection. | |
| Modificada | Alta (8.8) | 0.47% | — | Jizhicms | 14/10/2019 | 17/6/2026 | JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator. | |
| Modificada | Alta (7.5) | 1.3% | — | Idreamsoft Icms | 14/10/2019 | 17/6/2026 | idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer. | |
| Modificada | Crítica (9.8) | 1.1% | — | Idreamsoft Icms | 14/10/2019 | 17/6/2026 | An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload. | |
| Modificada | Media (5.4) | 0.61% | — | Xunruicms | 1/10/2019 | 17/6/2026 | An issue was discovered in XunRuiCMS 4.3.1. There is a stored XSS in the module_category area. | |
| Modificada | Media (6.5) | 0.47% | — | Idreamsoft Icms | 21/9/2019 | 17/6/2026 | An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF. | |
| Modificada | Alta (8.8) | 0.55% | — | Tuzicms | 21/9/2019 | 17/6/2026 | TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF. | |
| Modificada | Alta (8.8) | 0.55% | — | Tuzicms | 21/9/2019 | 17/6/2026 | TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF. | |
| Modificada | Media (6.1) | 0.75% | — | Tuzicms | 21/9/2019 | 17/6/2026 | TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/. | |
| Modificada | Crítica (9.8) | 1.4% | — | Tuzicms | 20/9/2019 | 17/6/2026 | App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring. | |
| Modificada | Crítica (9.8) | 1.7% | — | Yejiao Tuzicms | 20/9/2019 | 17/6/2026 | App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring. | |
| Modificada | Media (6.1) | 0.83% | — | Icmsdev Icms | 12/8/2019 | 17/6/2026 | iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. | |
| Modificada | Media (4.9) | 1.6% | — | Damicms | 10/7/2019 | 17/6/2026 | An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI. | |
| Modificada | Media (4.8) | 0.62% | — | 1234n Minicms | 5/7/2019 | 17/6/2026 | In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie. | |
| Modificada | Media (4.8) | 0.62% | — | 1234n Minicms | 5/7/2019 | 17/6/2026 | In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186. | |
| Modificada | Media (4.8) | 0.63% | — | 1234n Minicms | 5/7/2019 | 17/6/2026 | In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie. | |
| Modificada | Media (6.1) | 0.86% | — | 1234n Minicms | 3/7/2019 | 17/6/2026 | In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the tags box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, and CVE-2018-20520. | |
| Modificada | Media (6.1) | 3.5% | 💥 Exploit | Ulicms | 8/5/2019 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the error parameter to admin/index.php?action=favicon. | |
| Modificada | Media (6.1) | 0.83% | — | Idreamsoft Icms | 22/4/2019 | 17/6/2026 | An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter. |