Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | QcmsAI | 21/9/2026 | 22/9/2026 | A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed… | |
| Aplazada | Crítica (9.8) | 0.71% | — | QcmsAI | 17/8/2026 | 31/8/2026 | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code | |
| Analizada | Media (6.5) | 0.47% | — | Q-cms Qcms | 6/8/2025 | 17/6/2026 | A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of the "Name" parameter in the backend template editor. By manipulating the parameter, attackers can perform directory traversal and access sensitive files outside the intended… | |
| Modificada | Crítica (9.8) | 0.98% | — | Uqcms | 15/2/2023 | 17/6/2026 | SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num. | |
| Modificada | Alta (7.5) | 1.2% | — | Q-cms Qcms | 14/3/2020 | 17/6/2026 | An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1. | |
| Modificada | Alta (8.8) | 0.49% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. CSRF exists via the backend/user/admin/add.html URI. | |
| Modificada | Media (6.1) | 0.68% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070. | |
| Modificada | Media (4.8) | 0.53% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/category.php has XSS. | |
| Modificada | Media (4.8) | 0.53% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/album.php has XSS. | |
| Modificada | Media (4.8) | 0.53% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/news.php has XSS. | |
| Modificada | Media (4.8) | 0.53% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS. | |
| Modificada | Media (4.8) | 0.53% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/down.php has XSS. | |
| Modificada | Media (4.8) | 0.53% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/user.php has XSS. | |
| Modificada | Media (4.8) | 0.53% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/slideshow.php has XSS. | |
| Modificada | Media (4.8) | 0.53% | — | Q-cms Qcms | 6/8/2018 | 17/6/2026 | An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/system.php has XSS. | |
| Modificada | Media (5.4) | 0.51% | — | Qcms | 12/3/2018 | 17/6/2026 | QCMS version 3.0 has XSS via the title parameter to the /guest/index.html URI. | |
| Modificada | Media (5.4) | 0.51% | — | Qcms | 12/3/2018 | 17/6/2026 | QCMS version 3.0 has XSS via the webname parameter to the /backend/system.html URI. |