Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.57% | — | Chshcms Cscms | 9/6/2022 | 17/6/2026 | A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan. | |
| Modificada | Alta (8.8) | 0.95% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del. | |
| Modificada | Alta (8.8) | 0.95% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan. | |
| Modificada | Alta (8.8) | 0.95% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. | |
| Modificada | Alta (7.2) | 0.83% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save. | |
| Modificada | Alta (8.8) | 0.95% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy. | |
| Modificada | Alta (7.2) | 0.83% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save. | |
| Modificada | Crítica (9.8) | 12% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. | |
| Modificada | Alta (8.8) | 0.86% | — | Chshcms Cscms | 4/5/2022 | 17/6/2026 | Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin. | |
| Modificada | Alta (7.2) | 0.87% | — | Chshcms Cscms | 15/4/2022 | 17/6/2026 | Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy. | |
| Modificada | Alta (7.2) | 0.85% | — | Chshcms Cscms | 15/4/2022 | 17/6/2026 | Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan. |