Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
23.377 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.51% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application… | |
| Aplazada | Media (6.5) | 0.35% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint. | |
| Aplazada | Media (5.3) | 0.36% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint. | |
| Aplazada | Alta (8.1) | 0.53% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint. | |
| Aplazada | Media (5.3) | 0.34% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 9/9/2026 | Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request. | |
| Aplazada | Media (6.5) | 0.54% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints. | |
| Aplazada | Crítica (9.1) | 0.50% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=. | |
| Aplazada | Media (5.3) | 0.36% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 1/9/2026 | User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists. | |
| Analizada | Media (5.4) | 0.26% | — | Zephyrproject Zephyr | 26/8/2026 | 31/8/2026 | The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In tlv_mgmt_post_recv(), the PTP_MGMT_TIME case casts mgmt_tlv->data to a 10-byte struct ptp_timestamp and reads it (then byte-swaps and writes it back) without first checking that the TLV data field is… | |
| Analizada | Baja (3.1) | 0.26% | — | Zephyrproject Zephyr | 26/8/2026 | 31/8/2026 | The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes without validating that enough payload bytes remain before each access. The loop's only bound is rx_pos < len; after consuming the one-byte command id… | |
| Analizada | Media (4.3) | 0.24% | — | Zephyrproject Zephyr | 26/8/2026 | 31/8/2026 | The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only guarantees that the one-byte command id is in bounds; for the CLOCK_SYNC_CMD_APP_TIME (AppTimeAns) command the handler then reads a 4-byte time… | |
| Aplazada | Media (4.3) | 0.27% | — | Project ManagerAI | 26/8/2026 | 26/8/2026 | The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in one of its REST API routes, allowing any authenticated user, such as a subscriber, to read any other user's activity history along with their email address and the details… | |
| Aplazada | Media (5.4) | 0.23% | — | Project ManagerAI | 26/8/2026 | 26/8/2026 | The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards. | |
| Aplazada | Alta (7.5) | 0.40% | — | Project ManagerAI | 26/8/2026 | 26/8/2026 | The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting. | |
| Aplazada | Media (5.3) | 0.22% | — | Saasproject Booking PackageAI | 26/8/2026 | 26/8/2026 | The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price. | |
| Aplazada | Media (4.6) | 0.15% | — | Corvusproject CorvusskkAI | 26/8/2026 | 28/8/2026 | CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Simple Inventory SystemAI | 25/8/2026 | 26/8/2026 | A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Shopping SystemAI | 25/8/2026 | 26/8/2026 | A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/sumit_form.php. Such manipulation of the argument Success leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Pendiente de análisis | Media (5.9) | 0.51% | — | Zephyrproject ZephyrAI | 25/8/2026 | 26/8/2026 | The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without checking the strtok_r return value. When the server-supplied uid is empty or contains no - delimiter,… | |
| Aplazada | Media (4.8) | 0.36% | 💥 PoC | Ekushey Project Manager CRMAI | 25/8/2026 | 24/9/2026 | Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three places on that page: the content attribute of the description meta element, the title element, and the text of an h4 element in the page header. The h4… | |
| Pendiente de análisis | Alta (7.8) | 0.21% | — | SOS Project SOSAI | 25/8/2026 | 6/10/2026 | A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly… | |
| Pendiente de análisis | Media (6.5) | 0.78% | — | 389 Project 389 DS BaseAI | 25/8/2026 | 8/9/2026 | A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for… | |
| Analizada | Alta (8.1) | 0.23% | — | HBS Project HBS | 25/8/2026 | 6/10/2026 | hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes the placeholder… | |
| Aplazada | Media (6.5) | 0.38% | — | WP Project Manager PROAI | 25/8/2026 | 28/9/2026 | The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Alta (7.1) | 0.41% | — | Gitpython Project Gitpython | 25/8/2026 | 2/9/2026 | GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents… |