Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.26%—KindeditorAISem-cms SemcmsAI23/9/202624/9/2026
A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross site scripting. The attack may be initiated remotely. The exploit has been published…
AplazadaMedia (6.3)0.15%—Sem-cms SemcmsAI9/6/202623/7/2026
SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.
AplazadaAlta (7.5)0.39%—Sem-cms SemcmsAI9/6/202623/7/2026
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
AnalizadaBaja (2.1)0.38%—Sem-cms Semcms29/1/202617/6/2026
A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was…
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php.
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php.
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php.
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php.
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php.
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php.
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php.
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php.
ModificadaMedia (5.4)0.23%—Sem-cms Semcms14/7/20255/7/2026
SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php.
AnalizadaCrítica (9.8)0.50%—Sem-cms Semcms27/3/202517/6/2026
semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.
AnalizadaMedia (5.3)0.51%—Sem-cms Semcms8/1/202517/6/2026
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the file SEMCMS_Images.php of the component Image Library Management Page. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been…
AnalizadaBaja (3.8)0.29%—Sem-cms Semcms3/12/202417/6/2026
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
ModificadaMedia (4.9)0.55%—Sem-cms Semcms20/11/20245/7/2026
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
AnalizadaCrítica (9.8)0.51%—Sem-cms Semcms20/9/202417/6/2026
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
AnalizadaMedia (5.9)0.39%—Sem-cms Semcms4/6/202417/6/2026
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid parameter in Download.php.
AnalizadaAlta (7.5)0.70%—Sem-cms Semcms4/6/202417/6/2026
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.
AnalizadaMedia (6.5)0.57%—Sem-cms Semcms7/5/202417/6/2026
A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file function.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaAlta (7.1)0.47%—Sem-cms Semcms19/4/20249/7/2026
An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script.
AnalizadaCrítica (9.8)0.76%—Sem-cms Semcms19/4/202417/6/2026
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.
AnalizadaCrítica (9.8)1.2%—Sem-cms Semcms3/4/202417/6/2026
An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.
AnalizadaAlta (7.5)0.79%—Sem-cms Semcms3/4/202417/6/2026
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.