Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.64%—Aerocms Project Aerocms13/1/202617/6/2026
Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.
ModificadaMedia (5.4)0.38%—Aerocms Project Aerocms14/4/202317/6/2026
AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaAlta (7.5)1.4%—Aerocms Project Aerocms16/12/202217/6/2026
AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1.
ModificadaAlta (7.2)1.2%—Aerocms Project Aerocms16/12/202217/6/2026
In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server.
ModificadaAlta (7.2)0.86%—Aerocms Project Aerocms13/12/202217/6/2026
The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.
ModificadaMedia (6.5)0.33%—Aerocms Project Aerocms13/12/202217/6/2026
AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
ModificadaMedia (6.1)0.47%—Aerocms Project Aerocms13/12/202217/6/2026
AeroCMS v0.0.1 is vulnerable to ClickJacking.
ModificadaMedia (4.8)0.46%—Aerocms Project Aerocms13/12/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.
ModificadaMedia (4.9)0.76%—Aerocms Project Aerocms13/12/202217/6/2026
AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.
ModificadaAlta (7.5)0.79%—Aerocms Project Aerocms29/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.
ModificadaMedia (4.9)0.86%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.
ModificadaMedia (4.9)0.83%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
ModificadaMedia (4.9)0.78%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
ModificadaAlta (7.5)0.81%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.
ModificadaAlta (7.5)0.81%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
ModificadaAlta (8.8)1.2%—Aerocms Project Aerocms13/9/202217/6/2026
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (6.5)2.6%—Aerocms Project Aerocms31/8/202217/6/2026
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
ModificadaMedia (6.1)1.5%—Aerocms Project Aerocms8/4/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.
ModificadaMedia (4.8)1.1%—Aerocms Project Aerocms8/4/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.
ModificadaAlta (7.2)2.7%—Aerocms Project Aerocms8/4/202217/6/2026
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.