Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.26% | — | KindeditorAISem-cms SemcmsAI | 23/9/2026 | 24/9/2026 | A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross site scripting. The attack may be initiated remotely. The exploit has been published… | |
| Aplazada | Media (6.3) | 0.15% | — | Sem-cms SemcmsAI | 9/6/2026 | 23/7/2026 | SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php. | |
| Aplazada | Alta (7.5) | 0.39% | — | Sem-cms SemcmsAI | 9/6/2026 | 23/7/2026 | SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php. | |
| Analizada | Baja (2.1) | 0.38% | — | Sem-cms Semcms | 29/1/2026 | 17/6/2026 | A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was… | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php. | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php. | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php. | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php. | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php. | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php. | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php. | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php. | |
| Modificada | Media (5.4) | 0.23% | — | Sem-cms Semcms | 14/7/2025 | 5/7/2026 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php. | |
| Analizada | Crítica (9.8) | 0.50% | — | Sem-cms Semcms | 27/3/2025 | 17/6/2026 | semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php. | |
| Analizada | Media (5.3) | 0.51% | — | Sem-cms Semcms | 8/1/2025 | 17/6/2026 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Baja (3.8) | 0.29% | — | Sem-cms Semcms | 3/12/2024 | 17/6/2026 | Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page. | |
| Modificada | Media (4.9) | 0.55% | — | Sem-cms Semcms | 20/11/2024 | 5/7/2026 | SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component. | |
| Analizada | Crítica (9.8) | 0.51% | — | Sem-cms Semcms | 20/9/2024 | 17/6/2026 | SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php. | |
| Analizada | Media (5.9) | 0.39% | — | Sem-cms Semcms | 4/6/2024 | 17/6/2026 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php. | |
| Analizada | Alta (7.5) | 0.70% | — | Sem-cms Semcms | 4/6/2024 | 17/6/2026 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php. | |
| Analizada | Media (6.5) | 0.57% | — | Sem-cms Semcms | 7/5/2024 | 17/6/2026 | A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Alta (7.1) | 0.47% | — | Sem-cms Semcms | 19/4/2024 | 9/7/2026 | An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. | |
| Analizada | Crítica (9.8) | 0.76% | — | Sem-cms Semcms | 19/4/2024 | 17/6/2026 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component. | |
| Analizada | Crítica (9.8) | 1.2% | — | Sem-cms Semcms | 3/4/2024 | 17/6/2026 | An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file. | |
| Analizada | Alta (7.5) | 0.79% | — | Sem-cms Semcms | 3/4/2024 | 17/6/2026 | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php. |