Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

5178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.27%—Phpgurukul Medical Card Generation System23/5/202517/6/2026
Phpgurukul Medical Card Generation System v1.0 is vulnerable to HTML Injection in admin/contactus.php via the parameter pagedes.
ModificadaMedia (5.4)0.25%—Anujk305 Medical Card Generation System23/5/202517/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters.
ModificadaMedia (4.8)0.26%—Anujk305 Medical Card Generation System23/5/202517/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters.
AplazadaMedia (5.3)0.31%—EDB PglogicalAIEDB BDRAIEDB PGDAI22/5/202517/6/2026
When pglogical attempts to replicate data, it does not verify it is using a replication connection, which means a user with CONNECT access to a database configured for replication can execute the pglogical command to obtain read access to replicated tables. When pglogical runs it should verify it is running on a…
AplazadaMedia (4.3)0.23%—Quanticalabs CAR Park Booking SystemAI19/5/202517/6/2026
Missing Authorization vulnerability in QuanticaLabs Car Park Booking System for WordPress car-park-booking-system-for-wordpress.This issue affects Car Park Booking System for WordPress: from n/a through <= 2.6.
AnalizadaMedia (4.6)0.22%—Anujk305 Medical Card Generation System19/5/202517/6/2026
A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter.
AplazadaMedia (5.4)0.35%—Quanticalabs Css3 Compare Pricing TablesAI16/5/202517/6/2026
Missing Authorization vulnerability in QuanticaLabs CSS3 Compare Pricing Tables for WordPress css3_web_pricing_tables_grids allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CSS3 Compare Pricing Tables for WordPress: from n/a through <= 11.6.
AplazadaMedia (5.4)0.32%—Quanticalabs Css3 AccordionsAI16/5/202517/6/2026
Missing Authorization vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CSS3 Accordions for WordPress: from n/a through <= 3.0.
AplazadaAlta (7.1)0.14%—Quanticalabs Css3 AccordionsAI16/5/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Stored XSS.This issue affects CSS3 Accordions for WordPress: from n/a through <= 3.0.
AplazadaBaja (2.3)0.19%—Best Practical Solutions LLC Request TrackerAI5/5/202517/6/2026
Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptographic algorithm is used to protect emails sent with S/MIME encryption. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the…
AplazadaMedia (6.4)0.24%—Verticalresponse Newsletter WidgetAI3/5/202517/6/2026
The VerticalResponse Newsletter Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'verticalresponse' shortcode in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaAlta (7.1)0.29%—Maximevalette Ical FeedsAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in maximevalette iCal Feeds ical-feeds allows Reflected XSS.This issue affects iCal Feeds: from n/a through <= 1.5.3.
AnalizadaCrítica (10)99%⚠ Explotación activa💥 ExploitErlang/otpCisco Confd BasicCisco Network Services OrchestratorCisco Cloud Native Broadband Network Gateway+1916/4/202517/6/2026
Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain…
AnalizadaMedia (6.1)0.41%—Oracle CRM Technical Foundation15/4/202517/6/2026
Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.…
ModificadaAlta (7.8)0.29%—Autodesk Advance SteelAutodesk AutocadAutodesk Autocad ArchitectureAutodesk Autocad Electrical+1315/4/202517/6/2026
A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.38%—Autodesk Autocad MechanicalAutodesk Autocad MEPAutodesk Autocad Plant 3DAutodesk Civil 3D+815/4/202517/6/2026
A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
AnalizadaMedia (4.9)0.23%—Gnome Control CenterCanonical Ubuntu Linux15/4/202517/6/2026
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
AplazadaMedia (5)0.17%—Canonical Charmed Mysql K8S OperatorAI9/4/202517/6/2026
Charmed MySQL K8s operator is a Charmed Operator for running MySQL on Kubernetes. Before revision 221, the method for calling a SQL DDL or python based mysql-shell scripts can leak database users credentials. The method mysql-operator calls mysql-shell application rely on writing to a temporary script file containing…
AplazadaAlta (7.1)0.38%—Hivedigital Canonical AttachmentsAI9/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hivedigital Canonical Attachments canonical-attachments allows Reflected XSS.This issue affects Canonical Attachments: from n/a through <= 1.8.
AplazadaAlta (8.2)0.58%—Canonical Get-workflow-version-actionAI2/4/202517/6/2026
canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-version-action step fails, the exception output may include the GITHUB_TOKEN. If the full token is included in the exception output, GitHub…
AplazadaMedia (6.5)0.36%—Noor Alam Magical-blocksAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Blocks magical-blocks allows Stored XSS.This issue affects Magical Blocks: from n/a through <= 1.0.12.
AnalizadaAlta (7.5)0.43%—Canonical Linux-bluefield31/3/202517/6/2026
Running DDoS on tcp port 22 will trigger a kernel crash. This issue is introduced by the backport of a commit regarding nft_lookup without the subsequent fixes that were introduced after this commit. The resolution of this CVE introduces those commits to the linux-bluefield package.
AplazadaMedia (6.5)0.21%—Bramwaas Simple Google Icalendar WidgetAI27/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bramwaas Simple Google Calendar Outlook Events Block Widget simple-google-icalendar-widget allows Stored XSS.This issue affects Simple Google Calendar Outlook Events Block Widget: from n/a through <= 2.5.0.
AnalizadaMedia (5.5)0.14%—Canonical AccountsserviceCanonical Ubuntu Linux25/3/202517/6/2026
accountsservice no longer drops permissions when writting .pam_environment
AnalizadaMedia (5.1)0.32%—Phpgurukul Medical Card Generation System23/3/202517/6/2026
A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to cross site scripting. The attack may be initiated remotely. The…