Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

822 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.7)——Amazon Bedrock Agentcore Starter ToolkitAI6/10/20266/10/2026
Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated remote actor in the same AWS account to cause the environment of a user importing a Bedrock Agent to issue arbitrary outbound requests…
RecibidaAlta (8.8)——Amazon Bedrock Agentcore Starter ToolkitAI6/10/20266/10/2026
Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated…
AplazadaAlta (7.5)0.32%—Fivestarplugins Five Star Restaurant ReservationsAI5/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects Five Star Restaurant Reservations: from n/a through 2.7.24.
Pendiente de análisisCrítica (9.8)0.17%—Dromara NorthstarAI5/10/20266/10/2026
Northstar (dromara/northstar, quantitative trading platform) <= 9.1.1 enables the H2 Console but its auth interceptor only covers /northstar/**, so /h2-console is exposed with no authentication and the embedded H2 DB uses default sa / empty password. Any network-reachable attacker can run arbitrary system commands via…
AplazadaMedia (4.9)0.23%—Fivestarplugins Five Star Business Profile AND SchemaAI4/10/20266/10/2026
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and…
AplazadaAlta (7.1)0.16%—Five Star Restaurant ReviewsAI1/10/20261/10/2026
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in…
AplazadaMedia (6.9)0.29%—Yii2 Starter KITAI30/9/20261/10/2026
yii2-starter-kit through 4.2.0 fails to validate article publication status in the attachment-download endpoint, allowing unauthenticated attackers to download files from draft articles. Attackers can enumerate sequential attachment identifiers to retrieve files from unpublished articles without authentication or…
AplazadaCrítica (9.3)0.40%—Yii2 Starter KIT Yii2-starter-kitAI30/9/202630/9/2026
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii…
AplazadaAlta (8.7)0.39%—Yii2 Starter KITAI30/9/202630/9/2026
yii2-starter-kit through 4.2.0 fails to validate file types in the backend storage upload actions, allowing authenticated managers to upload PHP files. Attackers with manager role can upload PHP scripts to the web-accessible storage directory and request them to execute arbitrary code on the server.
AplazadaBaja (1.2)0.18%—Zhistaredu StartrainingAI27/9/202628/9/2026
A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing of the file application.yml. Such manipulation of the argument xss.enabled leads to cross site scripting. It is possible to launch the attack remotely. Attacks of this nature are highly…
AplazadaBaja (2)0.19%—Zhistaredu StartrainingAI27/9/202628/9/2026
A weakness has been identified in zhistaredu StarTraining up to 3.8.1. This vulnerability affects unknown code of the file du-common/src/main/java/com/edu/common/utils/file/MimeTypeUtils.java of the component Upload Endpoint. This manipulation of the argument File causes cross site scripting. It is possible to…
AplazadaBaja (2.1)0.20%—Zhistaredu StartrainingAI27/9/202630/9/2026
A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed of the file SysRoleServiceImpl.java of the component dataScope Endpoint. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has been released to…
AplazadaBaja (2.1)0.21%—Zhistaredu StartrainingAI27/9/202628/9/2026
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.isAdmin of the file edu-common/src/main/java/com/edu/common/core/domain/entity/SysUser.java of the component authRole Endpoint. The manipulation of the argument userId/roleIds leads to authorization…
AplazadaMedia (5.5)0.65%—Zhistaredu StartrainingAI25/9/202628/9/2026
A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the component api-docs Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been…
AplazadaMedia (5.5)0.63%—Zhistaredu StartrainingAI25/9/202628/9/2026
A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is publicly available and might be used. The…
AplazadaMedia (5.5)0.45%—Zhistaredu StartrainingAI25/9/202628/9/2026
A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be…
AplazadaAlta (7.5)0.26%—Star-citizen EmbedvideoAI24/9/202630/9/2026
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute…
AplazadaAlta (8.5)0.18%—Biostar Bios Update UtilityAI21/9/202622/9/2026
A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been…
AplazadaAlta (8.5)0.18%—Biostar Temperature Monitor UtilityAI21/9/202621/9/2026
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack…
AplazadaBaja (2.1)1.2%—Chengdu Feiyuxing Technology Feiyu Star Router B-mb5e202AI21/9/202622/9/2026
A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the…
AplazadaBaja (2)2.1%—Chengdu Feiyuxing Technology Feiyu Star Router B-mb5e202-210322-r11656AI21/9/202621/9/2026
A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac results in command injection. The attack may be launched remotely. The exploit has been…
AplazadaAlta (8.5)0.18%💥 PoCBiostar Valkyrie AuroraAI21/9/202621/9/2026
A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The…
AplazadaAlta (8.5)0.18%💥 PoCBiostar Vivid LED DJAI21/9/202621/9/2026
A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The…
AplazadaAlta (8.8)0.52%—Mitrastar Gpt-2741gnac-n2-svAI17/9/202622/9/2026
The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request for the endpoint /cgi-bin/device-management-utilities-internet.cgi.
AplazadaAlta (8.8)0.64%—Mitrastar Gpt-2742gx4x5v6-svAI15/9/202622/9/2026
An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code via the /cgi-bin/device-management-utilities-internet.cgi component
Orbitaley — Vulnerabilidades