Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▲ 14 respecto a la semana anterior
Críticas / altas1459▲ 324 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

47 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.11%—AMD RocmAMD Radeon SoftwareAMD Radeon PRO VII FirmwareAMD Radeon VII Firmware11/2/202617/6/2026
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.
AnalizadaAlta (7.1)0.11%—AMD RocmAMD Radeon SoftwareAMD Radeon VII FirmwareAMD Radeon PRO VII Firmware11/2/202617/6/2026
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.
ModificadaAlta (8.8)0.64%—Aerocms Project Aerocms13/1/202617/6/2026
Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.
AnalizadaMedia (5.3)0.26%—Pyrocms11/12/202517/6/2026
PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows attackers to inject malicious scripts. Attackers can insert a payload in the 'Redirect From' field to execute arbitrary JavaScript when administrators view the redirects page.
ModificadaCrítica (9.8)53%—Pyrocms4/8/202317/6/2026
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.
ModificadaMedia (5.4)0.38%—Aerocms Project Aerocms14/4/202317/6/2026
AeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and comment_content parameters at /post.php. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
ModificadaAlta (7.5)1.4%—Aerocms Project Aerocms16/12/202217/6/2026
AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1.
ModificadaAlta (7.2)1.2%—Aerocms Project Aerocms16/12/202217/6/2026
In AeroCms v0.0.1, there is an arbitrary file upload vulnerability at /admin/posts.php?source=edit_post , through which we can upload webshell and control the web server.
ModificadaAlta (7.2)0.86%—Aerocms Project Aerocms13/12/202217/6/2026
The approve parameter from the AeroCMS-v0.0.1 CMS system is vulnerable to SQL injection attacks.
ModificadaMedia (6.5)0.33%—Aerocms Project Aerocms13/12/202217/6/2026
AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
ModificadaMedia (6.1)0.47%—Aerocms Project Aerocms13/12/202217/6/2026
AeroCMS v0.0.1 is vulnerable to ClickJacking.
ModificadaMedia (4.8)0.46%—Aerocms Project Aerocms13/12/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.
ModificadaMedia (4.9)0.76%—Aerocms Project Aerocms13/12/202217/6/2026
AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.
ModificadaAlta (7.5)0.79%—Aerocms Project Aerocms29/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.
ModificadaCrítica (9)0.75%—Pyrocms25/11/20229/7/2026
PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.
ModificadaMedia (4.9)0.86%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the id parameter at \admin\post_comments.php. This vulnerability allows attackers to access database information.
ModificadaMedia (4.9)0.83%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
ModificadaMedia (4.9)0.78%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
ModificadaAlta (7.5)0.81%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.
ModificadaAlta (7.5)0.81%—Aerocms Project Aerocms22/11/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.
ModificadaAlta (8.8)1.2%—Aerocms Project Aerocms13/9/202217/6/2026
AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaMedia (6.5)2.6%—Aerocms Project Aerocms31/8/202217/6/2026
AeroCMS 0.1.1 is vulnerable to SQL Injection via the author parameter.
ModificadaMedia (6.1)0.51%—Pyrocms1/8/20229/7/2026
PyroCMS v3.9 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
ModificadaMedia (6.1)1.5%—Aerocms Project Aerocms8/4/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via view_all_comments.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comments text field.
ModificadaMedia (4.8)1.1%—Aerocms Project Aerocms8/4/202217/6/2026
AeroCMS v0.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Post Title text field.