Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.28% | — | AdminerAI | 26/9/2026 | 30/9/2026 | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/functions.inc.php. The port capture group requires pure digits anchored to the end of the string, so any server value with a non-digit tail fails the regex and falls back to returning the whole string… | |
| Pendiente de análisis | Media (5.3) | 0.31% | — | AdminerAI | 26/9/2026 | 30/9/2026 | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.0.0) is loaded, is vulnerable to pre-authentication server-side request forgery. An unauthenticated attacker can submit auth[driver]=clickhouse with auth[server] set to an arbitrary URL (for example… | |
| Pendiente de análisis | Media (6.9) | 0.31% | — | AdminerAI | 26/9/2026 | 28/9/2026 | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the optional Elasticsearch driver (plugins/drivers/elastic.php), fixed in 6.0.2. Because adminer/include/auth.inc.php invokes Driver::connect() before the login result is validated, an unauthenticated attacker… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | AdminerAI | 26/9/2026 | 28/9/2026 | Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpolated into JavaScript without proper escaping, allowing a malicious database server to execute arbitrary JavaScript in the authenticated Adminer origin. In co-located deployments where the database… | |
| Aplazada | Media (6.1) | 0.41% | — | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (format (rand XOR secret):rand), allowing anyone who observes a single CSRF token (e.g., via network sniffing, log files, Referrer header, or XSS) to recover the session secret with a single XOR operation… | |
| Aplazada | Crítica (9.3) | 0.90% | 💥 PoC | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is… | |
| Aplazada | Media (5.3) | 0.34% | — | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer before 5.4.3 inserts unsanitized database server version strings into script tags with valid CSP nonces without proper validation. Attackers controlling a rogue MySQL server can return crafted version strings that break out of the JavaScript context and execute arbitrary code, bypassing Content Security Policy… | |
| Aplazada | Alta (8.6) | 1.2% | — | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server. | |
| Aplazada | Alta (7.1) | 0.62% | — | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the… | |
| Aplazada | Alta (7.2) | 0.53% | — | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any files writable by the PHP process. | |
| Aplazada | Media (6.9) | 0.43% | — | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer before 5.5.0 contains a server-side request forgery vulnerability in the login form's server field validator, which only inspects leading integers for privileged ports and fails to reject non-numeric port values. Attackers can inject PDO DSN keys like host= and port= into the server parameter to bypass the… | |
| Aplazada | Media (5.3) | 0.29% | — | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no trusted-proxy check and no validation of the prefix value. An attacker can supply an absolute URL (e.g. X-Forwarded-Prefix: https://evil.example) that flows into Location redirect headers, the… | |
| Aplazada | Baja (2.3) | 0.39% | — | AdminerAI | 25/8/2026 | 8/9/2026 | Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GHSA-8478-xrj3-h9c2). The validation guard (bootstrap.inc.php) only rejects prefixes matching ^/[^/], blocking //evil.com but allowing values such as /\evil.com whose second character is a backslash.… | |
| Aplazada | Media (5.3) | 0.33% | — | AdminerAI | 25/8/2026 | 30/9/2026 | Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in the ns parameter of plugins/sql-log.php. An authenticated user can supply path traversal sequences in the ns parameter to write arbitrary .sql files with attacker-controlled content to any writable… | |
| Aplazada | Alta (7.2) | 0.72% | — | AdminerAI | 20/8/2026 | 1/9/2026 | Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific flaw exists within the multi_query method.… | |
| Aplazada | Media (6) | 0.43% | — | AdminerAI | 20/7/2026 | 23/7/2026 | Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured reverse proxy to downgrade SameSite… | |
| Analizada | Alta (7.5) | 1.9% | 💥 Exploit | Adminer | 9/2/2026 | 17/6/2026 | Adminer is open-source database management software. Adminer v5.4.1 and earlier has a version check mechanism where adminer.org sends signed version info via JavaScript postMessage, which the browser then POSTs to ?script=version. This endpoint lacks origin validation and accepts POST data from any source. An attacker… | |
| Analizada | Media (6.9) | 0.50% | — | Friendsofshopware Froshadminer | 9/2/2026 | 17/6/2026 | FroshAdminer is the Adminer plugin for Shopware Platform. Prior to 2.2.1, the Adminer route (/admin/adminer) was accessible without Shopware admin authentication. The route was configured with auth_required=false and performed no session validation, exposing the Adminer UI to unauthenticated users. This vulnerability… | |
| Analizada | Alta (8.6) | 0.73% | 💥 PoC | Adminer | 25/8/2025 | 17/6/2026 | Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g., using s:1000000000), leading to a PHP Object Injection issue. Remote, unauthenticated attackers can trigger this by sending a malicious serialized object, which forces excessive memory… | |
| Analizada | Alta (7.3) | 0.41% | — | Ari-soft ARI Adminer | 16/10/2024 | 17/6/2026 | The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including, 1.1.14. This makes it possible for unauthenticated attackers to call the files directly and perform a wide variety of unauthorized… | |
| Analizada | Media (6.9) | 0.41% | — | Adminerevo | 24/6/2024 | 17/6/2026 | Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker would not otherwise have access to. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.4. | |
| Analizada | Media (6.9) | 0.58% | — | Adminerevo | 24/6/2024 | 17/6/2026 | Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. The denial of service is subject to PHP configuration limits. Adminer is no longer supported, but this issue was fixed in AdminerEvo version… | |
| Modificada | Crítica (9.2) | 0.66% | — | Adminerevo | 21/6/2024 | 17/6/2026 | The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it. Adminer is no longer supported, but this issue was fixed in AdminerEvo version 4.8.3. | |
| Modificada | Alta (7.8) | 0.40% | — | Adminer Login Project Adminer Login | 20/6/2022 | 17/6/2026 | A vulnerability has been found in Adminer Login 1.4.4 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to improper access controls. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. | |
| Modificada | Alta (7.5) | 14% | 💥 PoC | AdminerDebian Linux | 5/4/2022 | 17/6/2026 | Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbitrary File Read on the remote server by requesting the Adminer to connect to a remote MySQL database. |