Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.39% | — | Ecisp Espcms | 27/6/2023 | 17/6/2026 | An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter. | |
| Modificada | Alta (7.2) | 0.63% | — | Ecisp Espcms | 17/2/2023 | 17/6/2026 | An issue was discovered in ESPCMS P8.21120101 after logging in to the background, there is a SQL injection vulnerability in the function node where members are added. | |
| Modificada | Media (5.4) | 0.55% | — | Espcms | 12/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in earclink ESPCMS P8.21120101. Affected is an unknown function of the component Content Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 1.6% | — | Ecisp Espcms | 10/11/2022 | 9/7/2026 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE. | |
| Modificada | Crítica (9.8) | 20% | — | Ecisp Espcms | 10/11/2022 | 9/7/2026 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION. | |
| Modificada | Crítica (9.8) | 1.6% | — | Ecisp Espcms | 10/11/2022 | 9/7/2026 | ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT. | |
| Modificada | Alta (7.2) | 1.9% | — | Ecisp Espcms-p8 | 30/6/2022 | 17/6/2026 | ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates. | |
| Modificada | Media (6.1) | 0.66% | — | Earclink Espcms-p8 | 28/9/2021 | 17/6/2026 | EARCLINK ESPCMS-P8 contains a cross-site scripting (XSS) vulnerability in espcms_web\espcms_load.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Ecisp Espcms-p8 | 24/8/2021 | 17/6/2026 | EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information. | |
| Modificada | Alta (7.5) | 1.2% | — | Earclink Espcms-p8 | 7/1/2019 | 17/6/2026 | EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. install_pack/espcms_public/espcms_db.php may allow retrieving sensitive information from the ESPCMS database. |