Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1062 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.43% | — | Goodlayers HostelAI | 23/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Blind SQL Injection.This issue affects Goodlayers Hostel: from n/a through <= 3.1.4. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Goodlayers HostelAI | 23/5/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in GoodLayers Goodlayers Hostel gdlr-hostel allows Object Injection.This issue affects Goodlayers Hostel: from n/a through <= 3.1.2. | |
| Analizada | Baja (3.3) | 0.32% | 💥 PoC | Artifex Ghostscript | 23/5/2025 | 17/6/2026 | gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext. | |
| Aplazada | Alta (7.1) | 0.22% | — | Bruno Cavalcante GhostwriterAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno Cavalcante Ghostwriter allows Reflected XSS.This issue affects Ghostwriter: from n/a through 1.4. | |
| Modificada | Crítica (9.1) | 0.44% | — | Phpgurukul Hostel Management System | 28/4/2025 | 5/7/2026 | A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change Password component. Improper handling of session data allows a Session Hijacking attack, exploitable remotely | |
| Analizada | Media (4.5) | 0.18% | — | Artifex Ghostscript | 26/4/2025 | 17/6/2026 | In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954. | |
| Aplazada | Alta (7.6) | 0.62% | — | Kibokolabs HostelAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bob Hostel hostel allows Blind SQL Injection.This issue affects Hostel: from n/a through <= 1.1.5.6. | |
| Analizada | Media (5.3) | 0.34% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted… | |
| Analizada | Media (5.1) | 0.40% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /product. The manipulation of the argument product_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.59% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListController of the file /mall/product/0/20. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uploadUserHeadImage. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Alta (7.1) | 0.31% | — | Kibokolabs HostelAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5. | |
| Aplazada | Alta (7.1) | 0.22% | — | Kibokolabs HostelAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel hostel allows Reflected XSS.This issue affects Hostel: from n/a through <= 1.1.5.5. | |
| Modificada | Crítica (9.8) | 0.69% | — | Wpplugins Hide MY WP Ghost | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through <= 5.4.01. | |
| Aplazada | Alta (7.5) | 1.0% | — | Designingmedia HostikoAI | 26/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a through < 30.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Designingmedia HostikoAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designingmedia Hostiko hostiko allows Reflected XSS.This issue affects Hostiko: from n/a through < 30.1. | |
| Analizada | Crítica (9.8) | 0.60% | — | Artifex Ghostscript | 25/3/2025 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp. | |
| Modificada | Crítica (9.8) | 0.59% | — | Artifex Ghostscript | 25/3/2025 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c. | |
| Modificada | Alta (7.8) | 0.29% | — | Artifex Ghostscript | 25/3/2025 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c. | |
| Analizada | Alta (7.8) | 0.26% | — | Artifex Ghostscript | 25/3/2025 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c. | |
| Analizada | Alta (7.8) | 0.22% | — | Artifex Ghostscript | 25/3/2025 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c. | |
| Modificada | Crítica (9.8) | 0.82% | — | Artifex Ghostscript | 25/3/2025 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c. | |
| Modificada | Crítica (9.8) | 0.59% | — | Artifex Ghostscript | 25/3/2025 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c. | |
| Modificada | Alta (7.8) | 0.30% | — | Artifex Ghostscript | 25/3/2025 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs during serialization of DollarBlend in a font, for base/write_t1.c and psi/zfapi.c. | |
| Aplazada | Media (4.3) | 0.21% | — | Odihost Easy 301 RedirectsAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in odihost Easy 301 Redirects odihost-easy-redirect-301 allows Cross Site Request Forgery.This issue affects Easy 301 Redirects: from n/a through <= 1.33. |