Vulnerabilities
Summary — last 7 days
New vulnerabilities2,753▼ 36 vs. last week
Critical / high1,269▼ 264 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)241▲ 206 vs. last week
6 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | High (7.2) | 0.92% | — | Supermicro-cms Project Supermicro-cms | 8/11/2023 | 6/17/2026 | An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php. | |
| Modified | Medium (4.9) | 0.55% | — | Supermicro-cms Project Supermicro-cms | 8/11/2023 | 6/17/2026 | An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in images.php. | |
| Modified | High (7.5) | 1.4% | — | Impliedbydesign IBD Micro CMS | 4/6/2009 | 6/16/2026 | Multiple SQL injection vulnerabilities in microcms-admin-login.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) allow remote attackers to execute arbitrary SQL commands via (1) the administrators_username parameter (aka the Username field) or (2) the administrators_pass parameter (aka the Password field). | |
| Modified | High (7.5) | 2.5% | 💥 Exploit | Impliedbydesign Micro-cms | 3/30/2009 | 6/16/2026 | microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify… | |
| Modified | Medium (6.8) | 0.95% | 💥 Exploit | Implied BY Design Micro CMS | 8/31/2007 | 6/16/2026 | SQL injection vulnerability in cms/revert-content.php in Implied by Design Micro CMS (Micro-CMS) 3.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modified | High (7.5) | 9.0% | 💥 Exploit | IBD Micro CMS | 6/22/2006 | 6/16/2026 | PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was later reported that this can also be leveraged to include and… |