Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
1742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.29% | — | Lybbn Django VUE LyadminAI | 5/10/2026 | 6/10/2026 | A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is… | |
| Recibida | Sin puntuar | 0.15% | — | FineadminAI | 5/10/2026 | 5/10/2026 | FineAdmin v1.0 was discovered to contain a SQL injection vulnerability via the field/order parameter at ButtonService.GetListByFilter(). This vulnerability allows attackers to access sensitive database information via crafted SQL statements. | |
| Recibida | Media (6.5) | 0.15% | — | ApiadminAI | 5/10/2026 | 6/10/2026 | ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter. | |
| Recibida | Sin puntuar | 0.35% | — | ApiadminAI | 5/10/2026 | 5/10/2026 | ApiAdmin v5.0 and before is vulnerable to Directory Traversal. The admin file-upload endpoint POST /admin/Index/upload in ApiAdmin takes the uploaded file's extension verbatim there is no whitelist, blacklist or content check and move_uploaded_file() drops the file into the web-accessible directory public/upload/Ymd/.… | |
| Aplazada | Media (4.3) | 0.16% | — | Brandtoss WP Admin AuditAI | 5/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Admin Audit: from n/a through 1.2.17. | |
| Aplazada | Alta (8.7) | 1.2% | — | MineadminAI | 30/9/2026 | 2/10/2026 | MineAdmin is a ready-to-use backend management system suitable for quickly building website backends, operation platforms, permission centers, internal management systems, CMS, CRM, OA, ERP and other business applications. Prior to version 3.2.0-alpha.2, the app-store plugin service concatenates unsanitized… | |
| Aplazada | Alta (7.6) | 0.28% | — | Admin Notices ManagerAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. | |
| Pendiente de análisis | Alta (8.7) | 0.26% | — | Tibco AdministratorAI | 29/9/2026 | 30/9/2026 | Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially crafted input through the web-based administration console. | |
| Aplazada | Alta (7.1) | 0.39% | — | FastadminAI | 29/9/2026 | 29/9/2026 | A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file application/database.php of the component Database Management. The manipulation results in execution with unnecessary privileges. The attack may be launched remotely. The exploit is now public and may… | |
| Pendiente de análisis | Media (6.9) | 0.28% | — | AdminerAI | 26/9/2026 | 30/9/2026 | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and falls back to returning the whole string… | |
| Pendiente de análisis | Media (5.3) | 0.31% | — | AdminerAI | 26/9/2026 | 30/9/2026 | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example… | |
| Pendiente de análisis | Media (6.9) | 0.31% | — | AdminerAI | 26/9/2026 | 28/9/2026 | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php invokes Driver::connect() before the login result is validated, an unauthenticated attacker… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | AdminerAI | 26/9/2026 | 28/9/2026 | Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In co-located deployments where the database… | |
| Aplazada | Baja (2) | 0.19% | — | Huanzi-qch Base-adminAI | 24/9/2026 | 24/9/2026 | A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\src\main\java\cn\huanzi\qch\baseadmin\common\controller\CommonController.java of the component Add User Handler. The manipulation of the argument… | |
| Aplazada | Media (6) | 0.41% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedded in the NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48. An authenticated user… | |
| Aplazada | Alta (8.1) | 0.45% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the authenticated user. An authenticated user who supplies another tenant's notifier… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id) without verifying that the maintenance entry belongs to the authenticated user's… | |
| Aplazada | Media (5.4) | 0.29% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 29/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, target-user consent, or target-user notification. Any authenticated user can force… | |
| Aplazada | Alta (8.1) | 0.49% | — | Sysadminsmedia HomeboxAI | 21/9/2026 | 23/9/2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of the caller's role in the active group, while the active group is selected through… | |
| Analizada | Alta (8.7) | 0.58% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning with a dash was… | |
| Analizada | Crítica (9.3) | 0.58% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ and, when that returned nothing, fell back… | |
| Analizada | Alta (7.1) | 0.35% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's Restore and Maintenance tools passed the client-supplied 'database' field directly as the value of the --dbname option given to pg_restore and psql. libpq expands a database name containing an equals sign into a full connection string, and connection keywords embedded in that value take precedence over the… | |
| Analizada | Media (6) | 0.32% | — | Pgadmin 4 | 17/9/2026 | 21/9/2026 | pgAdmin 4's File Manager save_file endpoint, which backs saving from the Query Tool and ERD, validated the requested path with Filemanager.check_access_permission() and then opened the file for writing with a plain open() call. CVE-2026-7819 had previously hardened the separate file upload path by opening its target… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Eduadmin BookingAI | 17/9/2026 | 17/9/2026 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. | |
| Analizada | Media (6.8) | 0.13% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |