Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.27%—KittycatfishAI9/6/202621/7/2026
KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the 'kc_ad' parameter in base.css.php or kittycatfish.php to extract sensitive database…
ModificadaMedia (6.8)0.32%—Catfishcms Project Catfishcms27/6/202317/6/2026
Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions via /index.php/admin/index/modifymanage.html.
ModificadaMedia (6.1)0.56%—Catfish-cms Catfish CMS15/12/202117/6/2026
Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admin/Index/addmenu.htmland then the .html file on the website that uses this editor (the file suffix is allowed).
ModificadaAlta (8.8)0.42%—Catfish-cms Catfish CMS15/12/202117/6/2026
Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.
ModificadaMedia (6.1)0.66%—Catfish-cms Catfish CMS23/6/202117/6/2026
A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gonggao" parameter.
ModificadaMedia (5.4)0.56%—Catfish-cms Catfish Blog29/10/201817/6/2026
An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
ModificadaAlta (8.8)0.52%—Catfish-cms Catfish Blog29/10/201817/6/2026
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
ModificadaAlta (8.8)0.49%—Catfish-cms Catfish CMS29/10/201817/6/2026
A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.
ModificadaMedia (5.4)0.53%—Catfish-cms Catfish CMS29/10/201817/6/2026
An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.
ModificadaMedia (4.8)0.53%—Catfish-cms Catfish CMS12/7/201817/6/2026
Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).
ModificadaMedia (5.4)0.64%—Catfish-cms Catfish CMS11/4/201817/6/2026
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
ModificadaMedia (4.6)0.42%—Catfish Project Catfish26/2/201417/6/2026
Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0 allows local users to gain privileges via a Trojan horse bin/catfish.py under the current working directory.
ModificadaMedia (4.6)0.42%—Catfish Project Catfish26/2/201417/6/2026
Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory.
ModificadaMedia (4.6)0.42%—Catfish Project Catfish26/2/201417/6/2026
Untrusted search path vulnerability in Catfish through 0.4.0.3, when a Fedora package such as 0.4.0.2-2 is not used, allows local users to gain privileges via a Trojan horse catfish.pyc in the current working directory.
ModificadaMedia (4.6)0.42%—Catfish Project Catfish26/2/201417/6/2026
Untrusted search path vulnerability in Catfish through 0.4.0.3 allows local users to gain privileges via a Trojan horse catfish.py in the current working directory.