Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.82% | — | BC Security EmpireAI | 16/9/2026 | 24/9/2026 | BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in the filename to bypass directory containment and write malicious files to sensitive… | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft AGE OF Empires II | 14/7/2026 | 24/7/2026 | Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. | |
| Analizada | Baja (2.1) | 0.37% | — | Phome Empirecms | 2/1/2026 | 1/10/2026 | A vulnerability has been found in EmpireSoft EmpireCMS up to 8.0. Impacted is the function CheckSaveTranFiletype of the file e/class/connect.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted… | |
| Analizada | Media (5.5) | 1.3% | — | Phome Empirecms | 2/1/2026 | 1/10/2026 | A flaw has been found in EmpireSoft EmpireCMS up to 8.0. This issue affects the function egetip of the file e/class/connect.php of the component IP Address Handler. This manipulation causes protection mechanism failure. The attack may be initiated remotely. The exploit has been published and may be used. The vendor… | |
| Aplazada | Media (6.5) | 0.26% | — | Phome EmpirebakAI | 14/8/2025 | 17/6/2026 | An issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the config file was loaded. | |
| Aplazada | Crítica (9.8) | 10% | — | BC Security EmpireAI | 27/6/2024 | 14/7/2026 | BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a… | |
| Aplazada | Media (6.5) | 0.40% | — | Themefreesia Freesia EmpireAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Freesia Empire allows Stored XSS.This issue affects Freesia Empire: from n/a through 1.4.1. | |
| Modificada | Alta (7.2) | 0.98% | — | Phome Empirecms | 9/1/2024 | 17/6/2026 | SQL injection vulnerability in EmpireCMS v7.5, allows remote attackers to execute arbitrary code and obtain sensitive information via the DoExecSql function. | |
| Modificada | Crítica (9.8) | 0.63% | — | Leadscloud Empirecms | 14/12/2023 | 17/6/2026 | EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php. | |
| Modificada | Crítica (9.8) | 0.96% | — | Phome Empirecms | 3/5/2022 | 17/6/2026 | EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php | |
| Modificada | Crítica (9.8) | 2.8% | — | Phome Empirecms | 17/8/2021 | 17/6/2026 | A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file. | |
| Modificada | Alta (7.2) | 2.2% | — | Phome Empirecms | 7/6/2019 | 17/6/2026 | admin\db\DoSql.php in EmpireCMS through 7.5 allows remote attackers to execute arbitrary PHP code via SQL injection that uses a .php filename in a SELECT INTO OUTFILE statement to admin/admin.php. | |
| Modificada | Media (4.8) | 0.92% | — | Phome Empirecms | 7/6/2019 | 17/6/2026 | admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php. | |
| Modificada | Media (6.1) | 0.83% | — | Phome Empirecms | 27/5/2019 | 17/6/2026 | EmpireCMS 7.5.0 has XSS via the HTTP Referer header to e/member/doaction.php. | |
| Modificada | Media (6.1) | 0.41% | — | Phome Empirecms | 27/5/2019 | 17/6/2026 | EmpireCMS 7.5.0 has XSS via the from parameter to e/member/doaction.php, as demonstrated by a CSRF payload that changes the dynamic page template. The attacker can choose to resend the e/template/member/regsend.php registered activation mail page. | |
| Modificada | Alta (8.8) | 0.65% | — | Phome Empirecms | 7/3/2019 | 17/6/2026 | EmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to CVE-2018-16339. | |
| Modificada | Crítica (9.8) | 1.6% | — | Phome Empirecms | 20/12/2018 | 17/6/2026 | Empire CMS 7.5 allows remote attackers to execute arbitrary PHP code via the ftemp parameter in an enews=EditMemberForm action because this code is injected into a memberform.$fid.php file. | |
| Modificada | Crítica (9.8) | 3.7% | — | Phome Empirecms | 31/10/2018 | 17/6/2026 | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter. | |
| Modificada | Alta (8.8) | 1.5% | — | Phome Empirecms | 9/10/2018 | 17/6/2026 | EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users. | |
| Modificada | Alta (8.8) | 0.52% | — | Phome Empirecms | 2/9/2018 | 17/6/2026 | An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser. | |
| Modificada | Media (5.3) | 2.2% | — | DedecmsPhome Empirecms | 12/2/2018 | 17/6/2026 | EmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php. | |
| Modificada | Media (5.3) | 1.8% | — | Phome Empirecms | 12/2/2018 | 17/6/2026 | EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php. | |
| Modificada | Media (6.8) | 2.2% | — | Phome Empirecms | 16/11/2012 | 16/6/2026 | Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template. | |
| Modificada | Alta (7.5) | 0.89% | — | Phome Empire CMS | 1/7/2009 | 16/6/2026 | SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid parameter to the default URI under e/tool/gbook/. | |
| Modificada | Media (5) | 1.0% | — | Empire Server | 14/7/2008 | 16/6/2026 | The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers to determine the PRNG seed. |