74cms
74cmsse: vulnerabilidades y CVE
74cmsse tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-42154 | Crítica (9.8) | 1.0% | — | 17 oct 2022 | An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2022-41472 | Media (5.4) | 0.42% | — | 17 oct 2022 | 74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted… |
| CVE-2022-41471 | Media (6.5) | 0.60% | — | 17 oct 2022 | 74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account. |
| CVE-2022-33097 | Alta (7.5) | 0.97% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job. |
| CVE-2022-33096 | Alta (7.5) | 0.97% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index. |
| CVE-2022-33095 | Alta (7.5) | 1.1% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. |
| CVE-2022-33094 | Alta (7.5) | 0.97% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map. |
| CVE-2022-33093 | Alta (7.5) | 0.97% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list. |
| CVE-2022-33092 | Alta (7.5) | 0.97% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index. |
| CVE-2022-32131 | Media (6.1) | 0.66% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /index/notice/show. |
| CVE-2022-32130 | Media (6.1) | 0.66% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/down_resume/total/nature. |
| CVE-2022-32129 | Media (6.1) | 0.66% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/account/safety/trade. |
| CVE-2022-32128 | Media (6.1) | 0.66% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/service/increment/add/im. |
| CVE-2022-32127 | Media (6.1) | 0.66% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total. |
| CVE-2022-32126 | Media (6.1) | 0.66% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company. |
| CVE-2022-32125 | Media (6.1) | 0.66% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job. |
| CVE-2022-32124 | Media (6.1) | 0.66% | — | 23 jun 2022 | 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfairol/show/. |
| CVE-2022-29721 | Alta (7.5) | 1.0% | — | 26 may 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist. |
| CVE-2022-29720 | Alta (7.5) | 0.96% | — | 26 may 2022 | 74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php. |