Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.7)0.17%—Geeeeeeeek Dingfanzu8/9/202517/6/2026
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addShop
AnalizadaCrítica (9.8)0.64%—Geeeeeeeek Dingfanzu15/4/202517/6/2026
A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at the "operateOrder.php" id parameter.
AplazadaMedia (5.3)0.31%—Dingfanzu CMSAI21/2/202517/6/2026
A vulnerability, which was classified as critical, was found in dingfanzu CMS up to 20250210. Affected is an unknown function of the file /ajax/loadShopInfo.php. The manipulation of the argument shopId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AplazadaAlta (7.1)0.20%—DingfanzucmsAI15/1/202517/6/2026
SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a local attacker to execute arbitrary code via not filtering the content correctly at the "checkOrder.php" shopId module.
AnalizadaCrítica (9.3)0.26%—Timgreen Dingfanzu CMS8/11/202417/6/2026
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin.
AnalizadaMedia (6.3)0.18%—Timgreen Dingfanzu CMS28/10/202417/6/2026
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17
AnalizadaMedia (6.3)0.18%—Timgreen Dingfanzu CMS28/10/202417/6/2026
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17
AnalizadaMedia (6.1)0.28%—Timgreen Dingfanzu CMS16/10/202417/6/2026
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the component doAdminAction.php which allows a remote attacker to execute arbitrary code
AplazadaMedia (5.3)0.32%—Dingfanzu CMSAI27/9/202417/6/2026
A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The…
AnalizadaMedia (4.7)0.21%—Timgreen Dingfanzu CMS25/9/202417/6/2026
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31
AnalizadaMedia (6.3)0.19%—Timgreen Dingfanzu CMS25/9/202417/6/2026
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate
AnalizadaMedia (5.3)0.49%—Gitapp Dingfanzu22/9/202417/6/2026
A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected is an unknown function of the file scripts/order.js of the component Order Checkout. The manipulation of the argument address-name leads to cross site scripting. It is possible to launch the…
AplazadaMedia (5.3)0.40%—Dingfanzu CMSAI29/8/202417/6/2026
A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. This affects an unknown part of the file /ajax/getBasicInfo.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaMedia (5.3)0.75%—Geeeeeeeek Dingfanzu29/8/202417/6/2026
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been rated as critical. Affected by this issue is some unknown functionality of the file /ajax/chpwd.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit…
AnalizadaMedia (6.9)0.76%—Gitapp Dingfanzu29/8/202417/6/2026
A vulnerability was found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /ajax/checkin.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely.…