Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Content Management SystemAI | 6/9/2026 | 8/9/2026 | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Aplazada | Baja (2.1) | 0.20% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.25% | — | Itsourcecode Content Management SystemAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument topic_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.1) | 0.21% | — | Zenar Content Management SystemAI | 17/5/2026 | 17/6/2026 | Zenar Content Management System contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating form parameters in POST requests. Attackers can inject script tags through the current_page parameter sent to the ajax.php endpoint, which reflects unsanitized… | |
| Aplazada | Media (5.1) | 0.53% | — | Navigate Content Management SystemAI | 21/4/2026 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user input is not properly sanitized through designed query parameters. This results in unsafe HTML rendering, which could allow a remote attacker to execute JavaScript… | |
| Aplazada | Baja (1.9) | 0.35% | — | Code-projects Simple Content Management SystemAI | 13/4/2026 | 17/6/2026 | A weakness has been identified in code-projects Simple Content Management System 1.0. This affects an unknown part of the file /web/admin/welcome.php. Executing a manipulation of the argument News Title can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple Content Management SystemAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Simple Content Management System 1.0. Affected by this issue is some unknown functionality of the file /web/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple Content Management SystemAI | 13/4/2026 | 17/6/2026 | A vulnerability was identified in code-projects Simple Content Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /web/admin/login.php. Such manipulation of the argument User leads to sql injection. The attack may be launched remotely. The exploit is publicly available and… | |
| Analizada | Media (5.5) | 3.6% | — | Defaultfuction Content Management System | 2/4/2026 | 17/6/2026 | A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be… | |
| Modificada | Crítica (9.8) | 0.37% | — | Globalmedya Content Management System | 29/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows Command Line Execution through SQL Injection. This issue affects Content Management System (CMS): through 21072025. | |
| Modificada | Media (6.1) | 0.21% | — | Globalmedya Content Management System | 29/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows XSS Through HTTP Headers. This issue affects Content Management System (CMS): through 21072025. | |
| Analizada | Media (5.5) | 0.39% | — | Code-projects Content Management System | 2/1/2026 | 17/6/2026 | A vulnerability was detected in code-projects Content Management System 1.0. The affected element is an unknown function of the file /pages.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Analizada | Baja (2) | 0.36% | — | Code-projects Content Management System | 2/1/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Content Management System 1.0. Impacted is an unknown function of the file /admin/edit_posts.php. The manipulation of the argument image leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit has been disclosed publicly… | |
| Modificada | Media (5.5) | 0.39% | — | Code-projects Content Management System | 2/1/2026 | 17/6/2026 | A weakness has been identified in code-projects Content Management System 1.0. This issue affects some unknown processing of the file /admin/delete.php. Executing a manipulation of the argument del can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.44% | — | Code-projects Content Management System | 2/1/2026 | 17/6/2026 | A vulnerability was determined in code-projects Content Management System 1.0. This impacts an unknown function of the file search.php. This manipulation of the argument Value causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2) | 0.34% | — | Anirbandutta News-buzzCode-projects Content Management System | 29/12/2025 | 17/6/2026 | A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Media (6.9) | 0.49% | — | Sitecore Experience PlatformAISitecore Content Management SystemAI | 25/7/2025 | 17/6/2026 | Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 (rev. 141226) and prior to 7.5 Update-1 (rev. 150130) contain a vulnerability that may allow an attacker to download files under the web root of the site when the name of the file is… | |
| Analizada | Media (5.3) | 0.48% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/users.php. The manipulation of the argument delete leads to sql injection. The attack may be launched remotely.… | |
| Analizada | Media (5.3) | 0.48% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/users.php. The manipulation of the argument change_to_admin leads to sql injection. The attack can be… | |
| Analizada | Media (6.9) | 0.58% | — | Anirbandutta9 News-buzzCode-projects Content Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. It has been classified as critical. Affected is an unknown function of the file /publicposts.php. The manipulation of the argument post leads to sql injection. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (6.1) | 0.37% | — | Motivian Content Management System | 4/6/2025 | 17/6/2026 | Cross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Marketing/Forms, Marketing/Offers and Content/Pages components. | |
| Analizada | Alta (8.2) | 0.59% | — | Motivian Content Management System | 4/6/2025 | 17/6/2026 | File Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the Content/Gallery/Images component. |