Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 48 respecto a la semana anterior
Críticas / altas1479▲ 371 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Earcms EAR | 29/8/2023 | 17/6/2026 | An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Arcms Project Arcms | 26/11/2018 | 17/6/2026 | An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php. | |
| Modificada | Crítica (9.8) | 1.5% | — | Arcms Project Arcms | 26/11/2018 | 17/6/2026 | An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images. | |
| Modificada | Alta (7) | 0.71% | — | Earcms EAR Music | 30/7/2017 | 17/6/2026 | In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code. | |
| Modificada | Media (6.8) | 2.3% | — | Lunarcms Lunar CMS | 3/7/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administrators for requests that (1) add Super users via a request to admin/user_create.php or conduct cross-site scripting (XSS) attacks via the (2) email or (3) subject… | |
| Modificada | Media (4.3) | 1.7% | — | Starcms | 19/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Cms.maury91 Solarcms | 27/2/2009 | 16/6/2026 | SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to indes.php. NOTE: some of these details are obtained from third party information. |