Vulnerabilities

Summary — last 7 days

New vulnerabilities2,819▼ 255 vs. last week
Critical / high1,321▼ 176 vs. last week
New active exploitation (KEV)8→ no change vs. last week
Unscored (no CVSS)207▼ 114 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.5)0.46%—SiemprecmsAI9/9/20256/17/2026
A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used.
DeferredMedium (5.5)0.33%—SiemprecmsAI9/9/20256/17/2026
A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
ModifiedMedium (6.8)2.6%💥 ExploitPrecoc Precms7/22/20086/16/2026
SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a UserProfil action.
Orbitaley — Vulnerabilities