Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
595 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.36% | — | Xjd2020 Fastcms | 16/2/2025 | 17/6/2026 | A vulnerability has been found in FastCMS up to 0.1.5 and classified as problematic. This vulnerability affects unknown code of the file /fastcms.html#/template/menu of the component Template Menu. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.5) | 0.87% | — | 1000mz Chestnutcms | 3/2/2025 | 17/6/2026 | ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory. | |
| Analizada | Alta (7.5) | 0.39% | — | 1000mz Chestnutcms | 3/2/2025 | 17/6/2026 | ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder. | |
| Analizada | Crítica (9.8) | 0.56% | — | 1000mz Chestnutcms | 3/2/2025 | 17/6/2026 | ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function. | |
| Analizada | Alta (8.1) | 22% | ⚠ Explotación activa | Craftcms Craft CMS | 18/1/2025 | 17/6/2026 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security… | |
| Analizada | Media (4.3) | 0.29% | — | Otcms | 17/1/2025 | 17/6/2026 | OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily. | |
| Analizada | Crítica (9.8) | 0.88% | — | 1000mz Chestnutcms | 6/1/2025 | 17/6/2026 | File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. This string is then passed to the memberService.uploadAvatarByBase64 method for processing. Within the service, the base64-encoded image is… | |
| Analizada | Media (5.3) | 0.50% | — | Pbootcms | 19/12/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to path traversal. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.56% | — | Pbootcms | 19/12/2024 | 17/6/2026 | A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.3) | 97% | ⚠ Explotación activa💥 Exploit | Craftcms Craft CMS | 18/12/2024 | 17/6/2026 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised… | |
| Analizada | Media (6.5) | 0.75% | — | Craftcms Craft CMS | 13/11/2024 | 17/6/2026 | Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Base64-encoded string. By embedding this function within a system… | |
| Analizada | Alta (7.2) | 1.2% | — | Craftcms Craft CMS | 13/11/2024 | 17/6/2026 | Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive folders as the file system, leading to potential file overwriting through… | |
| Analizada | Alta (7.2) | 1.4% | — | Craftcms Craft CMS | 13/11/2024 | 17/6/2026 | Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This vulnerability is fixed in 4.12.2 and 5.4.3. | |
| Aplazada | Alta (7.8) | 0.19% | — | FirebirdAIElefantcms ElefantAI | 8/11/2024 | 17/6/2026 | Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions. The default installation directory of Elefant is "C:\Elefant1" which is writable for all users. In addition, the… | |
| Aplazada | Crítica (9.8) | 0.70% | — | FirebirdAIElefantcms ElefantAI | 8/11/2024 | 17/6/2026 | An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enables an attacker to… | |
| Analizada | Media (5.4) | 0.35% | — | Instantcms | 29/10/2024 | 17/6/2026 | InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input validation taking place. Due to this attackers are able to inject the XSS (Cross Site Scripting) payload and execute. This vulnerability is fixed in 2.16.3. | |
| Analizada | Media (6.1) | 0.28% | — | Pbootcms | 28/10/2024 | 17/6/2026 | PbootCMS 3.2.8 is vulnerable to URL Redirect. | |
| Analizada | Media (4.8) | 0.25% | — | Wtcms Project Wtcms | 25/10/2024 | 17/6/2026 | An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't processed, resulting in Cross Site Scripting (XSS). | |
| Analizada | Media (4.7) | 0.29% | — | Wtcms Project Wtcms | 25/10/2024 | 17/6/2026 | WTCMS 1.0 is vulnerable to SQL Injection in the edit_post method of /Admin\Controller\NavControl.class.php via the parentid parameter. | |
| Analizada | Crítica (9.8) | 0.46% | — | Wtcms Project Wtcms | 25/10/2024 | 17/6/2026 | WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php. | |
| Analizada | Alta (7.2) | 0.58% | — | Modstart Mostartcms | 27/9/2024 | 17/6/2026 | ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an arbitrary website via a crafted URL. | |
| Analizada | Media (4.8) | 0.35% | — | Craftcms Craft CMS | 9/9/2024 | 17/6/2026 | Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input. | |
| Analizada | Media (6.9) | 0.82% | — | Ltcms | 13/8/2024 | 17/6/2026 | A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected by this vulnerability is the function downloadUrl of the file /api/file/downloadUrl of the component API Endpoint. The manipulation of the argument file leads to server-side request forgery. The attack can be launched… | |
| Analizada | Media (6.9) | 0.82% | — | Ltcms | 13/8/2024 | 17/6/2026 | A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical. Affected is the function multiDownload of the file /api/file/multiDownload of the component API Endpoint. The manipulation of the argument file leads to server-side request forgery. It is possible to launch the attack remotely.… | |
| Analizada | Media (6.9) | 0.95% | — | Ltcms | 13/8/2024 | 17/6/2026 | A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/downloadfile of the component API Endpoint. The manipulation of the argument file leads to path traversal. The attack may be initiated remotely. The exploit has been… |