Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.43% | — | Flatcore-cms | 9/11/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in flatCore-CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username text field. | |
| Modificada | Alta (8.8) | 1.4% | — | Flatcore-cms | 16/6/2022 | 17/6/2026 | flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code. | |
| Modificada | Crítica (9.8) | 19% | — | Flatcore-cms | 15/6/2022 | 17/6/2026 | flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities. | |
| Modificada | Media (5.4) | 0.48% | — | Flatcore-cms | 13/6/2022 | 17/6/2026 | flatCore-CMS version 2.0.8 is affected by Cross Site Scripting (XSS) in the "Create New Page" option through the index page. | |
| Modificada | Media (6.1) | 0.71% | — | Flatcore-cms | 6/6/2022 | 17/6/2026 | FlatCore-CMS 2.0.9 has a cross-site scripting (XSS) vulnerability in pages.edit.php through meta tags and content sections. | |
| Modificada | Media (6.6) | 1.1% | — | Flatcore-cms | 28/10/2021 | 17/6/2026 | flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type | |
| Modificada | Media (5.4) | 1.7% | — | Flatcore-cms | 23/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability exiss in FlatCore-CMS 2.0.7 via the upload image function. | |
| Modificada | Alta (7.2) | 46% | — | Flatcore-cms | 23/8/2021 | 17/6/2026 | Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code. | |
| Modificada | Media (6.1) | 0.84% | — | Flatcore-cms | 10/1/2018 | 17/6/2026 | flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-Agent string. | |
| Modificada | Alta (7.5) | 1.9% | — | Flatcore-cms | 10/5/2017 | 17/6/2026 | acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF. | |
| Modificada | Alta (7.5) | 1.0% | — | Flatcore-cms | 14/4/2017 | 17/6/2026 | SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database. | |
| Modificada | Crítica (9.8) | 1.0% | — | Flatcore-cms | 14/4/2017 | 17/6/2026 | SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read and write to the users database. | |
| Modificada | Alta (8.8) | 0.91% | — | Flatcore-cms | 14/4/2017 | 17/6/2026 | CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations. |