Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 299 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.86% | — | Icmsdev Icms | 20/9/2023 | 17/6/2026 | Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. | |
| Modificada | Alta (8.8) | 0.41% | — | Icmsdev Icms | 20/9/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files. | |
| Modificada | Media (6.1) | 0.83% | — | Icmsdev Icms | 12/8/2019 | 17/6/2026 | iCMS 7.0.15 allows admincp.php?app=apps XSS via the keywords parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Icmsdev Icms | 14/1/2019 | 17/6/2026 | An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data_id parameter. | |
| Modificada | Crítica (9.8) | 1.5% | — | Icmsdev Icms | 29/10/2018 | 17/6/2026 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. | |
| Modificada | Alta (8.8) | 0.66% | — | Icmsdev Icms | 1/9/2018 | 17/6/2026 | An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is validated, which can be bypassed via an admincp.php substring in this header. | |
| Modificada | Alta (7.5) | 1.5% | — | Icmsdev Icms | 27/8/2018 | 17/6/2026 | An SSRF vulnerability was discovered in idreamsoft iCMS 7.0.11 because the remote function in app/spider/spider_tools.class.php does not block DNS hostnames associated with private and reserved IP addresses, as demonstrated by 127.0.0.1 in an A record. NOTE: this vulnerability exists because of an incomplete fix for… | |
| Modificada | Alta (7.5) | 1.5% | — | Icmsdev Icms | 2/8/2018 | 17/6/2026 | An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not block private and reserved IP addresses such as 10.0.0.0/8. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-14514. | |
| Modificada | Crítica (9.8) | 1.6% | — | Icmsdev Icms | 23/7/2018 | 17/6/2026 | An SSRF vulnerability was discovered in idreamsoft iCMS V7.0.9 that allows attackers to read sensitive files, access an intranet, or possibly have unspecified other impact. | |
| Modificada | Media (6.1) | 0.83% | — | Icmsdev Icms | 20/7/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen. | |
| Modificada | Crítica (9.8) | 1.5% | — | Icmsdev Icms | 15/6/2018 | 17/6/2026 | spider.admincp.php in iCMS v7.0.8 has SQL Injection via the id parameter in an app=spider&do=batch request to admincp.php. | |
| Modificada | Media (5.4) | 0.61% | — | Icmsdev Icms | 20/4/2018 | 17/6/2026 | iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search. | |
| Modificada | Alta (8.8) | 0.59% | — | Icmsdev Icms | 19/4/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP. | |
| Modificada | Alta (8.8) | 0.53% | — | Icmsdev Icms | 16/4/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&frame=iPHP. | |
| Modificada | Media (5.4) | 0.62% | — | Icmsdev Icms | 10/4/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS through 7.0.7. XSS exists via the nickname field in an admincp.php?app=user&do=save&frame=iPHP request. | |
| Modificada | Crítica (9.8) | 1.4% | — | Icmsdev Icms | 10/4/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS through 7.0.7. SQL injection exists via the pid array parameter in an admincp.php?app=tag&do=save&frame=iPHP request. | |
| Modificada | Alta (8.8) | 0.60% | — | Icmsdev Icms | 10/4/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save&frame=iPHP request. | |
| Modificada | Media (5.3) | 1.1% | — | Icmsdev Icms | 10/4/2018 | 17/6/2026 | An issue was discovered in idreamsoft iCMS through 7.0.7. Physical path leakage exists via an invalid nickname field that reveals a core/library/weixin.class.php pathname. | |
| Modificada | Alta (7.5) | 2.0% | — | Wmsdesign Wmscms | 17/6/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search, (2) sbr, (3) pid, (4) sbl, and (5) FilePath parameters to default.asp; and the (6) sbr, (7) pr, and (8) psPrice parameters to printpage.asp. | |
| Modificada | Media (4.3) | 3.0% | — | Wmsdesign Wmscms | 17/6/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) sbr, (3) p, and (4) sbl parameters, different vectors than CVE-2007-3137. | |
| Modificada | Alta (9) | 35% | — | Microsoft Data EngineMicrosoft SQL ServerMicrosoft SQL Server Desktop EngineMicrosoft Wmsde+2 | 8/7/2008 | 16/6/2026 | Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB… | |
| Modificada | Media (5) | 11% | — | Microsoft Data EngineMicrosoft SQL ServerMicrosoft SQL Server Desktop EngineMicrosoft Wmsde+1 | 8/7/2008 | 16/6/2026 | SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to… | |
| Modificada | Media (5.1) | 2.6% | — | Cmsdevelopment Business Card WEB Builder | 23/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.99, and possibly 2.5 Beta and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | |
| Modificada | Alta (10) | 87% | — | Compaq Insight ManagerCompaq Insight Manager XEMicrosoft Data EngineMicrosoft Msde | 12/8/2002 | 16/6/2026 | The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, which allows remote attackers… | |
| Modificada | Alta (7.5) | 23% | — | Microsoft MsdeMicrosoft SQL Server | 23/7/2002 | 16/6/2026 | Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure." |