Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.35% | — | EyoucmsAI | 29/6/2026 | 29/6/2026 | A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processing of the file /index.php of the component API. Such manipulation of the argument click_like leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and… | |
| Aplazada | Media (5.5) | 0.41% | — | EyoucmsAI | 29/4/2026 | 17/6/2026 | A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of the file application/common.php. The manipulation of the argument sort_asc leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The… | |
| Aplazada | Baja (2) | 0.41% | — | EyoucmsAI | 29/4/2026 | 17/6/2026 | A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File Handler. Executing a manipulation can lead to code injection. The attack can be launched remotely. The exploit has been made available to the… | |
| Aplazada | Baja (2) | 0.38% | — | EyoucmsAI | 19/4/2026 | 17/6/2026 | A vulnerability was detected in EyouCMS up to 1.7.1. This issue affects the function edit_adminlogo of the file application/admin/controller/Index.php. Performing a manipulation of the argument filename results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may… | |
| Aplazada | Baja (2) | 0.33% | — | GougucmsAI | 1/4/2026 | 17/6/2026 | A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.41% | — | GougucmsAI | 1/4/2026 | 17/6/2026 | A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registration Handler. Such manipulation of the argument level leads to dynamically-determined object attributes. The attack may be performed from… | |
| Analizada | Baja (2) | 0.70% | — | Muyucms | 24/2/2026 | 17/6/2026 | A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the component Template Management Page. This manipulation of the argument temn/tp causes path traversal. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.53% | — | Eyoucms | 18/1/2026 | 17/6/2026 | A weakness has been identified in EyouCMS up to 1.7.1/5.0. Impacted is the function check_userinfo of the file Diyajax.php of the component Member Avatar Handler. Executing a manipulation of the argument viewfile can lead to unrestricted upload. The attack may be performed from remote. The exploit has been made… | |
| Modificada | Baja (2.1) | 0.45% | — | Eyoucms | 31/12/2025 | 17/6/2026 | A flaw has been found in EyouCMS up to 1.7.7. The impacted element is the function unserialize of the file application/api/controller/Ajax.php of the component arcpagelist Handler. Executing a manipulation of the argument attstr can lead to deserialization. The attack can be launched remotely. The exploit has been… | |
| Modificada | Baja (2) | 0.26% | — | Eyoucms | 31/12/2025 | 17/6/2026 | A vulnerability was detected in EyouCMS up to 1.7.7. The affected element is an unknown function of the file application/home/model/Ask.php of the component Ask Module. Performing a manipulation of the argument content results in cross site scripting. The attack can be initiated remotely. The exploit is now public and… | |
| Modificada | Baja (2.1) | 0.26% | — | Eyoucms | 31/12/2025 | 17/6/2026 | A security vulnerability has been detected in EyouCMS up to 1.7.7. Impacted is the function saveRemote of the file application/function.php. Such manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor is… | |
| Modificada | Baja (2) | 0.38% | — | Eyoucms | 28/12/2025 | 17/6/2026 | A security flaw has been discovered in EyouCMS up to 1.7.6. The affected element is an unknown function of the file /application/admin/logic/FilemanagerLogic.php of the component Backend Template Management. The manipulation of the argument content results in sql injection. It is possible to launch the attack… | |
| Analizada | Alta (7.5) | 0.43% | — | Eyoucms | 3/12/2025 | 17/6/2026 | XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request. | |
| Analizada | Baja (2.1) | 4.2% | — | Wenkucms Project Wenkucms | 29/9/2025 | 30/9/2026 | A vulnerability was found in mirweiye wenkucms up to 3.4. This impacts the function createPathOne of the file app/common/common.php. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.1) | 0.40% | — | Muyucms | 26/9/2025 | 17/6/2026 | A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the component Template Management. The manipulation results in code injection. It is possible to launch the attack remotely. | |
| Aplazada | Baja (2.1) | 0.26% | — | MuyucmsAI | 22/9/2025 | 17/6/2026 | A vulnerability was found in MuYuCMS up to 2.7. Impacted is an unknown function of the file /index/index.html of the component Add Fiend Link Handler. Performing manipulation of the argument Link URL results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and… | |
| Aplazada | Baja (1.9) | 0.27% | — | IbuyucmsAI | 15/9/2025 | 17/6/2026 | A vulnerability was identified in IbuyuCMS up to 2.6.3. Impacted is an unknown function of the file /admin/article.php?a=mod of the component Add Article Page. The manipulation of the argument Title leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and… | |
| Modificada | Media (6.1) | 0.19% | — | Eyoucms | 14/8/2025 | 5/7/2026 | EyouCMS 1.7.3 is vulnerale to Cross Site Scripting (XSS) in index.php, which can be exploited to obtain sensitive information. | |
| Modificada | Media (6.1) | 0.23% | — | Eyoucms | 7/8/2025 | 5/7/2026 | EyouCMS 1.6.7 is vulnerable to Cross Site Scripting (XSS) in /login.php?m=admin&c=System&a=web&lang=cn. | |
| Aplazada | Media (4.8) | 0.31% | — | GougucmsAI | 17/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in gougucms 4.08.18. This affects the function add of the file /admin/department/add of the component Add Department Page. The manipulation of the argument title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Alta (7.5) | 0.39% | — | Sucms Project Sucms | 27/2/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a crafted GET request. | |
| Analizada | Alta (7.5) | 0.67% | — | Sucms Project Sucms | 27/2/2025 | 17/6/2026 | An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafted GET request. | |
| Aplazada | Alta (7.1) | 0.20% | — | DingfanzucmsAI | 15/1/2025 | 17/6/2026 | SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module. | |
| Analizada | Media (5.3) | 0.65% | — | Sucms Project Sucms | 9/1/2025 | 17/6/2026 | A vulnerability was found in Sucms 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/admin_members.php?ac=search. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (5.1) | 0.62% | — | Eyoucms | 14/11/2024 | 17/6/2026 | A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was… |