Записи Seacms
114 опубликованных записей вендора seacms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')25
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-94 Improper Control of Generation of Code ('Code Injection')18
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
114 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2022-27336Эксплойта нет | Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.seacms · seacms | Критическая9,8 | — | 20,5 % | 27 апр. 2022 г. |
40В плане | CVE-2024-29275Proof of concept | SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive iseacms · seacms · CWE-89 | Критическая9,8 | — | 5,0 % | 22 мар. 2024 г. |
40В плане | CVE-2021-37358Эксплойта нет | SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=checseacms · seacms · CWE-89 | Критическая9,8 | — | 2,3 % | 18 авг. 2021 г. |
40В плане | CVE-2022-23878Эксплойта нет | seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.seacms · seacms | Критическая9,8 | — | 2,2 % | 2 мар. 2022 г. |
40В плане | CVE-2020-21378Proof of concept | SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.seacms · seacms · CWE-89 | Критическая9,8 | — | 2,1 % | 21 дек. 2020 г. |
39Наблюдать | CVE-2023-44171Эксплойта нет | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.seacms · seacms · CWE-22 | Критическая9,8 | — | 1,4 % | 27 сент. 2023 г. |
39Наблюдать | CVE-2023-44170Эксплойта нет | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.seacms · seacms · CWE-22 | Критическая9,8 | — | 1,4 % | 27 сент. 2023 г. |
39Наблюдать | CVE-2023-44169Эксплойта нет | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.seacms · seacms · CWE-22 | Критическая9,8 | — | 1,4 % | 27 сент. 2023 г. |
39Наблюдать | CVE-2023-43216Эксплойта нет | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.seacms · seacms · CWE-22 | Критическая9,8 | — | 1,4 % | 27 сент. 2023 г. |
39Наблюдать | CVE-2023-44172Эксплойта нет | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.seacms · seacms · CWE-22 | Критическая9,8 | — | 1,4 % | 27 сент. 2023 г. |
39Наблюдать | CVE-2018-16822Эксплойта нет | SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.seacms · seacms · CWE-89 | Критическая9,8 | — | 1,2 % | 21 сент. 2018 г. |
39Наблюдать | CVE-2023-46010Эксплойта нет | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.seacms · seacms · CWE-94 | Критическая9,8 | — | 1,2 % | 25 окт. 2023 г. |
39Наблюдать | CVE-2024-55461Эксплойта нет | SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().seacms · seacms · CWE-77 | Критическая9,8 | — | 1,1 % | 18 дек. 2024 г. |
39Наблюдать | CVE-2018-16445Эксплойта нет | An issue was discovered in SeaCMS through 6.61.seacms · seacms · CWE-89 | Критическая9,8 | — | 1,1 % | 4 сент. 2018 г. |
39Наблюдать | CVE-2024-39028Эксплойта нет | An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.seacms · seacms · CWE-77 | Критическая9,8 | — | 1,1 % | 5 июл. 2024 г. |
39Наблюдать | CVE-2024-46640Эксплойта нет | SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp.seacms · seacms · CWE-94 | Критическая9,8 | — | 1,0 % | 20 сент. 2024 г. |
39Наблюдать | CVE-2023-0960Эксплойта нет | SeaCMS Picture Management config.ftp.php deserializationseacms · seacms · CWE-502 | Критическая9,8 | — | 1,0 % | 22 февр. 2023 г. |
39Наблюдать | CVE-2025-44071Эксплойта нет | SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php.seacms · seacms · CWE-94 | Критическая9,8 | — | 1,0 % | 5 мая 2025 г. |
39Наблюдать | CVE-2023-43222Эксплойта нет | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.seacms · seacms · CWE-94 | Критическая9,8 | — | 1,0 % | 27 сент. 2023 г. |
39Наблюдать | CVE-2022-43256Эксплойта нет | SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.seacms · seacms · CWE-89 | Критическая9,8 | — | 0,9 % | 16 нояб. 2022 г. |
39Наблюдать | CVE-2021-39426Эксплойта нет | An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 paraseacms · seacms · CWE-94 | Критическая9,8 | — | 0,9 % | 15 дек. 2022 г. |
39Наблюдать | CVE-2025-22974Эксплойта нет | SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter iseacms · seacms · CWE-89 | Критическая9,8 | — | 0,8 % | 24 февр. 2025 г. |
39Наблюдать | CVE-2024-44921Эксплойта нет | SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.seacms · seacms · CWE-89 | Критическая9,8 | — | 0,6 % | 3 сент. 2024 г. |
39Наблюдать | CVE-2024-44721Эксплойта нет | SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.seacms · seacms · CWE-918 | Критическая9,8 | — | 0,6 % | 9 сент. 2024 г. |
39Наблюдать | CVE-2025-25513Эксплойта нет | Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.seacms · seacms · CWE-89 | Критическая9,8 | — | 0,5 % | 24 февр. 2025 г. |
- CVE-2022-2733645В плане
Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 21 %seacms · seacms27 апр. 2022 г.
- CVE-2024-2927540В плане
SQL injection vulnerability in SeaCMS version 12.9, allows remote unauthenticated attackers to execute arbitrary code and obtain sensitive i
КритическаяCVSS 9,8Proof of conceptEPSS 5 %seacms · seacms22 мар. 2024 г.
- CVE-2021-3735840В плане
SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_ajax.php?action=chec
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %seacms · seacms18 авг. 2021 г.
- CVE-2022-2387840В плане
seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %seacms · seacms2 мар. 2022 г.
- CVE-2020-2137840В плане
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %seacms · seacms21 дек. 2020 г.
- CVE-2023-4417139Наблюдать
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms27 сент. 2023 г.
- CVE-2023-4417039Наблюдать
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms27 сент. 2023 г.
- CVE-2023-4416939Наблюдать
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms27 сент. 2023 г.
- CVE-2023-4321639Наблюдать
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms27 сент. 2023 г.
- CVE-2023-4417239Наблюдать
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms27 сент. 2023 г.
- CVE-2018-1682239Наблюдать
SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms21 сент. 2018 г.
- CVE-2023-4601039Наблюдать
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms25 окт. 2023 г.
- CVE-2024-5546139Наблюдать
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms18 дек. 2024 г.
- CVE-2018-1644539Наблюдать
An issue was discovered in SeaCMS through 6.61.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms4 сент. 2018 г.
- CVE-2024-3902839Наблюдать
An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms5 июл. 2024 г.
- CVE-2024-4664039Наблюдать
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms20 сент. 2024 г.
- CVE-2023-096039Наблюдать
SeaCMS Picture Management config.ftp.php deserialization
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms22 февр. 2023 г.
- CVE-2025-4407139Наблюдать
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms5 мая 2025 г.
- CVE-2023-4322239Наблюдать
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms27 сент. 2023 г.
- CVE-2022-4325639Наблюдать
SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms16 нояб. 2022 г.
- CVE-2021-3942639Наблюдать
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 para
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms15 дек. 2022 г.
- CVE-2025-2297439Наблюдать
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter i
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms24 февр. 2025 г.
- CVE-2024-4492139Наблюдать
SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms3 сент. 2024 г.
- CVE-2024-4472139Наблюдать
SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms9 сент. 2024 г.
- CVE-2025-2551339Наблюдать
Seacms <=13.3 is vulnerable to SQL Injection in admin_members.php.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %seacms · seacms24 февр. 2025 г.