Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.43%—Hongcms Project Hongcms20/6/202317/6/2026
Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter.
ModificadaMedia (6.1)0.41%—Hongcms Project Hongcms28/4/202317/6/2026
Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.
ModificadaAlta (7.2)0.93%—Hongcms Project Hongcms1/7/202217/6/2026
An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.
ModificadaAlta (7.2)0.93%—Hongcms Project Hongcms1/7/202217/6/2026
An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.
ModificadaAlta (8.1)1.1%—Hongcms Project Hongcms26/4/202217/6/2026
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.
ModificadaMedia (6.5)0.94%—Hongcms Project Hongcms4/10/202117/6/2026
HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.
ModificadaCrítica (9.8)1.7%—Hongcms Project Hongcms18/5/202117/6/2026
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."
ModificadaMedia (6.1)1.0%—Hongcms Project Hongcms16/10/201917/6/2026
HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.
ModificadaMedia (6.1)1.0%—Hongcms Project Hongcms16/10/201917/6/2026
HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.
ModificadaMedia (6.1)1.0%—Hongcms Project Hongcms16/10/201917/6/2026
HongCMS 3.0.0 has XSS via the install/index.php dbusername parameter.
ModificadaMedia (6.1)1.0%—Hongcms Project Hongcms16/10/201917/6/2026
HongCMS 3.0.0 has XSS via the install/index.php dbname parameter.
ModificadaMedia (6.1)1.0%—Hongcms Project Hongcms16/10/201917/6/2026
HongCMS 3.0.0 has XSS via the install/index.php servername parameter.
ModificadaMedia (6.5)1.1%—Hongcms Project Hongcms25/9/201917/6/2026
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/database/ajax?action=delete, a similar issue to CVE-2018-16774. (If the attacker deletes config.php and visits install/index.php, they can reinstall the product.)
ModificadaMedia (6.5)1.5%—Hongcms Project Hongcms17/2/201917/6/2026
HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php/language/edit URI.
ModificadaAlta (7.5)1.6%—Hongcms Project Hongcms10/9/201817/6/2026
HongCMS 3.0.0 allows arbitrary file deletion via a ../ in the file parameter to admin/index.php/language/ajax?action=delete.
ModificadaAlta (7.2)2.2%—Hongcms Project Hongcms29/6/201817/6/2026
An issue was discovered in HongCMS 3.0.0. There is an Arbitrary Script File Upload issue that can result in PHP code execution via the admin/index.php/template/upload URI.
ModificadaAlta (7.2)2.6%—Hongcms Project Hongcms27/6/201817/6/2026
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.
ModificadaMedia (6.1)0.71%—Hongcms Project Hongcms13/6/201817/6/2026
system\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.
ModificadaMedia (4.8)0.53%—Hongcms Project Hongcms26/4/201817/6/2026
An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field.
ModificadaAlta (8.8)0.45%—Hongcms Project Hongcms22/4/201817/6/2026
An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.