Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

21.609 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (4.8)——Apache YunikornAI7/10/20267/10/2026
Apache YuniKorn 1.9.0 and earlier allows bypassing the check for the user annotation by setting a secondary label on the pod. If the pod has the label 'app=yunikorn' the checks limiting the user annotation content are not run. The label is used to identify the YuniKorn application itself in the deployments. The bypass…
RecibidaBaja (2)——Apache YunikornAI7/10/20267/10/2026
Apache YuniKorn 1.9.0 and earlier does not implement label and user annotation checks for workload UPDATE action bypassing all checks. Workloads in YuniKorn are defined as the following Kubernetes objects: "deployments", "replicasets", "statefulsets", "daemonsets", "jobs", "cronjobs". The CREATE action correctly…
RecibidaBaja (2.1)——Apache YunikornAI7/10/20267/10/2026
Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries.If the LDAP server returns a group membership entry, memberOf attribute, for a user specified in the pod the server crashes if a membership record does not start with…
RecibidaAlta (8.8)——Koinonia LinkAI7/10/20267/10/2026
The Koinonia Link WordPress plugin before 1.1.5 does not check that a user is allowed to change roles before saving a role selection submitted with a profile update, allowing any authenticated user, such as a subscriber, to grant themselves the Administrator role.
RecibidaMedia (6.8)——Wpmart Animated Number CountersAI7/10/20267/10/2026
The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a SQL query that runs when any unauthenticated visitor renders a page containing the counter, leading to second-order SQL injection that can read arbitrary data…
RecibidaAlta (7.7)——AMD Rocm Communication Collectives LibraryAI6/10/20266/10/2026
Improper input validation in the AMD ROCm Communication Collectives Library (RCCL) could allow a compromised peer rank or network-adjacent attacker to dereference an attacker-controlled pointer, potentially resulting in remote code execution.
RecibidaAlta (7.1)——Juniper Cloudvision CUEAI6/10/20266/10/2026
Improper validation of selected CloudVision CUE application programming interface (API) request parameters may allow an authenticated network user to perform SQL injection against the backend impacting its availability.
Pendiente de análisisAlta (7.1)——Quasar IcongenieAI6/10/20266/10/2026
Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to @quasar/icongenie 6.1.1, the icongenie generate --profile command accepted folder and name values from a user-supplied profile without constraining the resolved destination to the Quasar project directory.…
AplazadaBaja (2.1)——Kusalkasilva Learning Management SystemAI6/10/20266/10/2026
A vulnerability was identified in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. This affects an unknown function of the file search_class.php. Such manipulation of the argument school_year leads to sql injection. The attack may be launched remotely. The exploit is publicly…
AplazadaMedia (5.3)——Pusula Communication Expert MailAI6/10/20266/10/2026
Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects Expert Mail: through 2026-09-18.
AplazadaMedia (5.5)——Kusalkasilva Learning Management SystemAI6/10/20266/10/2026
A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The impacted element is an unknown function of the file student_signup.php of the component Student Registration Endpoint. This manipulation causes sql injection. The attack may be initiated…
AplazadaMedia (5.5)——Kusalkasilva Learning Management SystemAI6/10/20266/10/2026
A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of the component Administrator Login Endpoint. The manipulation of the argument username/password results in sql injection.…
AplazadaMedia (5.5)——Kusalkasilva Learning Management SystemAI6/10/20266/10/2026
A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated…
AplazadaAlta (8.2)0.11%—Danielberkompas CloakAI6/10/20266/10/2026
Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking vulnerability in danielberkompas cloak allows an attacker with write access to stored ciphertext to make it decrypt to a chosen value via bit flipping. Cloak.Ciphers.AES.CTR encrypts with AES-256 in CTR mode and stores the key…
AplazadaMedia (6.3)0.26%—Danielberkompas Cloak EctoAIDanielberkompas CloakAI6/10/20266/10/2026
Use of Password Hash With Insufficient Computational Effort vulnerability in danielberkompas cloak_ecto and danielberkompas cloak allows an attacker who holds the hashed values and the configured secret to brute-force low-entropy plaintexts much faster than configured. The dump/1 callback that Cloak.Ecto.PBKDF2…
AplazadaAlta (7.1)0.19%—Nicdark Hotel BookingAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Hotel Booking <= 3.8 versions.
AplazadaAlta (7.1)0.24%—Joomunited WP Media FolderAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in WP Media folder <= 6.2.2 versions.
AplazadaAlta (7.5)0.20%—Morning-pro MorningAI6/10/20266/10/2026
Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
AplazadaBaja (2.1)0.20%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A weakness has been identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. The affected element is an unknown function of the file book.php of the component Booking Handler. This manipulation of the argument Doctor/appointment causes sql injection. The attack is…
AplazadaCrítica (9.8)0.35%—Viewsonic ViewboardAI5/10/20266/10/2026
There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints
AplazadaAlta (7.5)0.27%—Viewsonic ViewboardAI5/10/20266/10/2026
There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search Endpoint. The manipulation of the argument doctorname leads to sql injection. Remote…
AplazadaMedia (5.5)0.33%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing a manipulation of the argument countryid/townid/cid/didval/cidval can lead to sql…
AplazadaMedia (5.5)0.26%—Anisha Online Appointment Booking SystemAI5/10/20266/10/2026
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing a manipulation of the argument uname/pass results in sql injection. The attack may be…