Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.64% | — | Aerocms Project Aerocms | 13/1/2026 | 17/6/2026 | Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system. | |
| Modificada | Media (5.4) | 0.38% | — | Aerocms Project Aerocms | 14/4/2023 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a crafted payload. | |
| Modificada | Alta (7.5) | 1.4% | — | Aerocms Project Aerocms | 16/12/2022 | 17/6/2026 | AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1. | |
| Modificada | Alta (7.2) | 1.2% | — | Aerocms Project Aerocms | 16/12/2022 | 17/6/2026 | In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server. | |
| Modificada | Alta (7.2) | 0.86% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks. | |
| Modificada | Media (6.5) | 0.33% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Media (6.1) | 0.47% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | AeroCMS v0.0.1 is vulnerable to ClickJacking. | |
| Modificada | Media (4.8) | 0.46% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field. | |
| Modificada | Media (4.9) | 0.76% | — | Aerocms Project Aerocms | 13/12/2022 | 17/6/2026 | AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter. | |
| Modificada | Alta (7.5) | 0.79% | — | Aerocms Project Aerocms | 29/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information. | |
| Modificada | Media (4.9) | 0.86% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information. | |
| Modificada | Media (4.9) | 0.83% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information. | |
| Modificada | Media (4.9) | 0.78% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information. | |
| Modificada | Alta (7.5) | 0.81% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information. | |
| Modificada | Alta (7.5) | 0.81% | — | Aerocms Project Aerocms | 22/11/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information. | |
| Modificada | Alta (8.8) | 1.2% | — | Aerocms Project Aerocms | 13/9/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (6.5) | 2.6% | — | Aerocms Project Aerocms | 31/8/2022 | 17/6/2026 | AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter. | |
| Modificada | Media (6.1) | 1.5% | — | Aerocms Project Aerocms | 8/4/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field. | |
| Modificada | Media (4.8) | 1.1% | — | Aerocms Project Aerocms | 8/4/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field. | |
| Modificada | Alta (7.2) | 2.7% | — | Aerocms Project Aerocms | 8/4/2022 | 17/6/2026 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the Post Image function under the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. |