Vulnerabilities
Summary — last 7 days
New vulnerabilities2,819▼ 255 vs. last week
Critical / high1,321▼ 176 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)207▼ 114 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.5) | 0.46% | — | SiemprecmsAI | 9/9/2025 | 6/17/2026 | A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Deferred | Medium (5.5) | 0.33% | — | SiemprecmsAI | 9/9/2025 | 6/17/2026 | A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Modified | Medium (6.8) | 2.6% | 💥 Exploit | Precoc Precms | 7/22/2008 | 6/16/2026 | SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a UserProfil action. |