Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

272 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.79%—Codeastro Restaurant POS System1/11/202217/6/2026
Restaurant POS System v1.0 was discovered to contain a SQL injection vulnerability via update_customer.php.
ModificadaAlta (7.2)1.2%—Codeastro Restaurant POS System1/11/202217/6/2026
An arbitrary file upload vulnerability in add_product.php of Restaurant POS System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
ModificadaAlta (7.5)0.92%—Obdasystems Mastro21/6/202217/6/2026
OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.
ModificadaAlta (7.5)1.3%—Obdasystems Mastro21/6/202217/6/2026
XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.
ModificadaCrítica (9.8)26%💥 ExploitCodeastrology WOO Product Table18/4/202217/6/2026
The Product Table for WooCommerce (wooproducttable) WordPress plugin before 3.1.2 does not have authorisation and CSRF checks in the wpt_admin_update_notice_option AJAX action (available to both unauthenticated and authenticated users), as well as does not validate the callback parameter, allowing unauthenticated…
ModificadaCrítica (9.8)2.7%💥 ExploitSaxum2003 Astro17/2/201817/6/2026
SQL Injection exists in the Saxum Astro 4.0.14 component for Joomla! via the publicid parameter.
ModificadaMedia (5.4)0.27%—Metago Astro File Manager With Cloud9/9/201417/6/2026
The ASTRO File Manager with Cloud (aka com.metago.astro) application ASTRO-4.4.592 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.9)0.40%—Pedro Castro Gnome-subtitles20/10/201016/6/2026
gnome-subtitles 1.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
ModificadaMedia (4.3)1.7%💥 ExploitRamoncastro Siestta4/5/201016/6/2026
Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter.
ModificadaMedia (6.8)2.3%💥 ExploitRamoncastro Siestta4/5/201016/6/2026
Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.
ModificadaMedia (4.3)1.5%💥 ExploitPhpscriptsnow Astrology10/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web script or HTML via the day parameter.
ModificadaAlta (7.5)2.6%💥 ExploitMole-group Gastro Portal (restaurant Directory) Script5/3/201016/6/2026
admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows remote attackers to change the admin password via an unspecified form submission.
ModificadaMedia (6.8)1.9%💥 ExploitCastro XL Torrentvolve17/6/200916/6/2026
Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. (dot dot) in the deleteTorrent parameter.
ModificadaAlta (7.5)1.0%💥 ExploitAstrospaces21/10/200816/6/2026
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.
ModificadaMedia (4.3)1.6%—Astrocam5/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in pic.php in AstroCam 2.5.0 through 2.7.3 allows remote attackers to inject arbitrary web script or HTML via the picfile parameter.
ModificadaMedia (4.3)1.5%💥 ExploitAstrosoft Helpdesk6/2/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for…
ModificadaAlta (7.5)1.9%—David Castro Apache Authcas13/12/200716/6/2026
SQL injection vulnerability in the David Castro AuthCAS module (AuthCAS.pm) 0.4 for the Apache HTTP Server allows remote attackers to execute arbitrary SQL commands via the SESSION_COOKIE_NAME (session ID) in a cookie.
ModificadaAlta (7.8)1.9%—Astrocam13/3/200716/6/2026
The web interface in AstroCam 2.0.0 through 2.6.5 allows remote attackers to cause a denial of service (daemon shutdown) via requests that contain a large amount of data in the "a" variable, which "fills up the message queue."
ModificadaAlta (7.5)1.4%—Astrodog Press Some Chess10/7/200616/6/2026
Multiple SQL injection vulnerabilities in AstroDog Press Some Chess 1.5-RC2 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors, possibly including the gameID parameter in board.php.
ModificadaBaja (2.6)1.3%—Astrodog Press Some Chess28/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in menu.php in Some Chess 1.5 rc1 allows remote attackers to inject arbitrary web script or HTML via the user parameter ("New Name" field).
ModificadaMedia (5)1.0%—Astrodog Press Some Chess28/6/200616/6/2026
Cross-site request forgery (CSRF) vulnerability in menu.php in Some Chess 1.5 rc2 allows remote attackers to conduct actions as another user, such as changing usernames and passwords, via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaAlta (10)3.3%—Astrocam31/12/200216/6/2026
astrocam.cgi in AstroCam 0.9-1-1 through 1.4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request. NOTE: earlier disclosures stated that the affected versions were 1.7.1 through 2.1.2, but the vendor explicitly stated that these were incorrect.
Orbitaley — Vulnerabilidades