Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.96% | — | Tuzicms | 26/1/2023 | 17/6/2026 | Tuzicms v2.0.6 was discovered to contain a SQL injection vulnerability via the component \App\Manage\Controller\UserController.class.php. | |
| Modificada | Crítica (9.8) | 0.78% | — | Tuzicms Project Tuzicms | 12/1/2023 | 17/6/2026 | A vulnerability classified as critical was found in TuziCMS 2.0.6. This vulnerability affects the function delall of the file \App\Manage\Controller\KefuController.class.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Crítica (9.8) | 0.73% | — | Tuzicms Project Tuzicms | 12/1/2023 | 17/6/2026 | A vulnerability classified as critical has been found in TuziCMS 2.0.6. This affects the function index of the file App\Manage\Controller\ArticleController.class.php of the component Article Module. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Modificada | Crítica (9.8) | 1.1% | — | Tuzicms | 28/3/2022 | 17/6/2026 | TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Yejiao Tuzicms | 24/3/2022 | 17/6/2026 | TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Yejiao Tuzicms | 3/12/2021 | 17/6/2026 | SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.class.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Yejiao Tuzicms | 3/12/2021 | 17/6/2026 | SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Yejiao Tuzicms | 3/12/2021 | 17/6/2026 | SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php. | |
| Modificada | Alta (8.8) | 0.55% | — | Tuzicms | 21/9/2019 | 17/6/2026 | TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF. | |
| Modificada | Alta (8.8) | 0.55% | — | Tuzicms | 21/9/2019 | 17/6/2026 | TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF. | |
| Modificada | Media (6.1) | 0.75% | — | Tuzicms | 21/9/2019 | 17/6/2026 | TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/. | |
| Modificada | Crítica (9.8) | 1.4% | — | Tuzicms | 20/9/2019 | 17/6/2026 | App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= substring. | |
| Modificada | Crítica (9.8) | 1.7% | — | Yejiao Tuzicms | 20/9/2019 | 17/6/2026 | App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/group?id= substring. | |
| Modificada | Alta (8.8) | 0.51% | — | Tuzicms | 17/4/2018 | 17/6/2026 | An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated by a history.pushState call. |