Vulnerabilities

Summary — last 7 days

New vulnerabilities2,753▼ 36 vs. last week
Critical / high1,269▼ 264 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)241▲ 206 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedHigh (7.2)0.92%—Supermicro-cms Project Supermicro-cms8/11/20236/17/2026
An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.
ModifiedMedium (4.9)0.55%—Supermicro-cms Project Supermicro-cms8/11/20236/17/2026
An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php.
ModifiedHigh (7.5)1.4%—Impliedbydesign IBD Micro CMS4/6/20096/16/2026
Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) allow remote attackers to execute arbitrary SQL commands via (1) the administrators_username parameter (aka the Username field) or (2) the administrators_pass parameter (aka the Password field).
ModifiedHigh (7.5)2.5%💥 ExploitImpliedbydesign Micro-cms3/30/20096/16/2026
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify…
ModifiedMedium (6.8)0.95%💥 ExploitImplied BY Design Micro CMS8/31/20076/16/2026
SQL injection vulnerability in cms/revert-content.php in Implied by Design Micro CMS (Micro-CMS) 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModifiedHigh (7.5)9.0%💥 ExploitIBD Micro CMS6/22/20066/16/2026
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was later reported that this can also be leveraged to include and…
Orbitaley — Vulnerabilities