Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.41%—QcmsAI21/9/202622/9/2026
A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed…
AplazadaCrítica (9.8)0.71%—QcmsAI17/8/202631/8/2026
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
AnalizadaMedia (6.5)0.47%—Q-cms Qcms6/8/202517/6/2026
A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend template editor. By manipulating the parameter, attackers can perform directory traversal and access sensitive files outside the intended…
ModificadaCrítica (9.8)0.98%—Uqcms15/2/202317/6/2026
SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.
ModificadaAlta (7.5)1.2%—Q-cms Qcms14/3/202017/6/2026
An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.
ModificadaAlta (8.8)0.49%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI.
ModificadaMedia (6.1)0.68%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070.
ModificadaMedia (4.8)0.53%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS.
ModificadaMedia (4.8)0.53%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS.
ModificadaMedia (4.8)0.53%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS.
ModificadaMedia (4.8)0.53%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.
ModificadaMedia (4.8)0.53%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS.
ModificadaMedia (4.8)0.53%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS.
ModificadaMedia (4.8)0.53%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS.
ModificadaMedia (4.8)0.53%—Q-cms Qcms6/8/201817/6/2026
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS.
ModificadaMedia (5.4)0.51%—Qcms12/3/201817/6/2026
QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI.
ModificadaMedia (5.4)0.51%—Qcms12/3/201817/6/2026
QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI.