Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.19% | — | OfcmsAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in OFCMS 1.1.3. The affected element is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SysUserController.java of the component JSON Query Interface. This manipulation causes sql injection. The attack may be initiated remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.20% | — | OfcmsAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in OFCMS 1.1.3. Impacted is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemParamController.java of the component JSON Query Interface. The manipulation results in sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.19% | — | OfcmsAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in OFCMS 1.1.3. This issue affects the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemDictController.java of the component JSON Query Interface. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.20% | — | OfcmsAI | 31/5/2026 | 22/7/2026 | A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component ComnController. Performing a manipulation of the argument system.user.query results in sql injection. The… | |
| Analizada | Media (5.3) | 0.29% | — | Ofcms Project Ofcms | 22/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.5) | 0.73% | — | Ofcms Project Ofcms | 25/10/2024 | 17/6/2026 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file | |
| Analizada | Media (6.5) | 0.73% | — | Ofcms Project Ofcms | 25/10/2024 | 17/6/2026 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file. | |
| Analizada | Media (5.3) | 0.37% | — | Ofcms Project Ofcms | 1/10/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.65% | — | Ofcms Project Ofcms | 14/5/2024 | 17/6/2026 | OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. | |
| Modificada | Media (5.4) | 0.45% | — | Ofcms Project Ofcms | 16/1/2024 | 17/6/2026 | Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component. | |
| Modificada | Alta (8.8) | 0.84% | — | Ofcms Project Ofcms | 16/3/2023 | 17/6/2026 | An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. | |
| Modificada | Media (6.1) | 0.57% | — | Ofcms Project Ofcms | 2/6/2022 | 17/6/2026 | OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. | |
| Modificada | Media (5.4) | 0.44% | — | Ofcms Project Ofcms | 10/4/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box. | |
| Modificada | Media (5.4) | 0.47% | — | Ofcms Project Ofcms | 10/4/2022 | 17/6/2026 | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information. | |
| Modificada | Alta (8.8) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI. | |
| Modificada | Alta (7.2) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI. | |
| Modificada | Alta (7.2) | 1.3% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. | |
| Modificada | Alta (8.8) | 2.6% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command. | |
| Modificada | Alta (7.2) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI. | |
| Modificada | Alta (8.8) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/upload URI. | |
| Modificada | Media (6.5) | 1.4% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name parameter). This is related to the save function… | |
| Modificada | Media (4.3) | 1.4% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java. | |
| Modificada | Alta (8.8) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/editUploadImage URI. | |
| Modificada | Alta (8.8) | 2.7% | — | Ofcms Project Ofcms | 6/3/2019 | 17/6/2026 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadImage URI. |