Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.89% | — | Mkcms Project Mkcms | 3/11/2022 | 17/6/2026 | MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter. | |
| Modificada | Crítica (9.8) | 0.89% | — | Mkcms Project Mkcms | 3/11/2022 | 17/6/2026 | MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter. | |
| Modificada | Crítica (9.8) | 0.89% | — | Mkcms Project Mkcms | 3/11/2022 | 17/6/2026 | MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter. | |
| Modificada | Alta (8.8) | 1.8% | — | Mkcms Project Mkcms | 18/4/2019 | 17/6/2026 | MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which triggers e-mail transmission with the password, as demonstrated by 123456. | |
| Modificada | Alta (8.8) | 0.61% | — | Mkcms Project Mkcms | 11/4/2019 | 17/6/2026 | MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mkcms Project Mkcms | 2/4/2019 | 17/6/2026 | MKCMS V5.0 has SQL injection via the bplay.php play parameter. |