Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.27% | — | KittycatfishAI | 9/6/2026 | 21/7/2026 | KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the 'kc_ad' parameter in base.css.php or kittycatfish.php to extract sensitive database… | |
| Modificada | Media (6.8) | 0.32% | — | Catfishcms Project Catfishcms | 27/6/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions via /index.php/admin/index/modifymanage.html. | |
| Modificada | Media (6.1) | 0.56% | — | Catfish-cms Catfish CMS | 15/12/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed). | |
| Modificada | Alta (8.8) | 0.42% | — | Catfish-cms Catfish CMS | 15/12/2021 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column. | |
| Modificada | Media (6.1) | 0.66% | — | Catfish-cms Catfish CMS | 23/6/2021 | 17/6/2026 | A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gonggao" parameter. | |
| Modificada | Media (5.4) | 0.56% | — | Catfish-cms Catfish Blog | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in catfish blog 2.0.33, related to "write source code." | |
| Modificada | Alta (8.8) | 0.52% | — | Catfish-cms Catfish Blog | 29/10/2018 | 17/6/2026 | A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33. | |
| Modificada | Alta (8.8) | 0.49% | — | Catfish-cms Catfish CMS | 29/10/2018 | 17/6/2026 | A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30. | |
| Modificada | Media (5.4) | 0.53% | — | Catfish-cms Catfish CMS | 29/10/2018 | 17/6/2026 | An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999. | |
| Modificada | Media (4.8) | 0.53% | — | Catfish-cms Catfish CMS | 12/7/2018 | 17/6/2026 | Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator). | |
| Modificada | Media (5.4) | 0.64% | — | Catfish-cms Catfish CMS | 11/4/2018 | 17/6/2026 | Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment). | |
| Modificada | Media (4.6) | 0.42% | — | Catfish Project Catfish | 26/2/2014 | 17/6/2026 | Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0 allows local users to gain privileges via a Trojan horse bin/catfish.py under the current working directory. | |
| Modificada | Media (4.6) | 0.42% | — | Catfish Project Catfish | 26/2/2014 | 17/6/2026 | Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory. | |
| Modificada | Media (4.6) | 0.42% | — | Catfish Project Catfish | 26/2/2014 | 17/6/2026 | Untrusted search path vulnerability in Catfish through 0.4.0.3, when a Fedora package such as 0.4.0.2-2 is not used, allows local users to gain privileges via a Trojan horse catfish.pyc in the current working directory. | |
| Modificada | Media (4.6) | 0.42% | — | Catfish Project Catfish | 26/2/2014 | 17/6/2026 | Untrusted search path vulnerability in Catfish through 0.4.0.3 allows local users to gain privileges via a Trojan horse catfish.py in the current working directory. |