Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
9809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.75% | — | Inventory-management-system-phpAI | 5/8/2026 | 26/8/2026 | Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Miantang Iot-phpAI | 5/8/2026 | 26/8/2026 | Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select * from userlists where username='' and password='' limit 1"). An unauthenticated attacker can submit a payload such as pwd='… | |
| Pendiente de análisis | Crítica (9.8) | 0.80% | — | HPE Networking Sd-wan OrchestratorAI | 4/8/2026 | 6/8/2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target… | |
| Pendiente de análisis | Crítica (9.8) | 0.80% | — | HPE Networking Sd-wan OrchestratorAI | 4/8/2026 | 6/8/2026 | Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target… | |
| Aplazada | Crítica (9.3) | 0.58% | — | Atlas-livreAIPHPAI | 4/8/2026 | 24/9/2026 | Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke destructive admin actions such as record… | |
| Aplazada | Baja (2.1) | 0.32% | — | Chetans9 Core-php-admin-panelAI | 4/8/2026 | 12/8/2026 | A flaw has been found in chetans9 core-php-admin-panel up to 90d07ed5aac5e0f09b6a5828d7bb2eb83010763f. This issue affects some unknown processing of the file /Applications/MAMP/htdocs/core-php-admin-panel-master/customers.php. Executing a manipulation of the argument filter_col can lead to sql injection. The attack… | |
| Pendiente de análisis | Alta (7.2) | 0.37% | — | Guzzlephp GuzzleAI | 3/8/2026 | 8/9/2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl… | |
| Pendiente de análisis | Media (6.5) | 0.20% | — | Guzzlephp GuzzleAI | 3/8/2026 | 8/9/2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport… | |
| Aplazada | Alta (8.1) | 0.40% | — | Zblogcn Z-blogphpAI | 3/8/2026 | 9/9/2026 | A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature. | |
| Analizada | Media (5.7) | 0.30% | — | Tp-link Omada Fusion 2.5g FirmwareTp-link Omada Er707-m2 FirmwareTp-link Omada Er7206 FirmwareTp-link Omada Er706w Firmware+105 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials to gain unauthorized access to affected devices… | |
| Analizada | Media (5.8) | 0.31% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. Successful exploitation may allow disclosure of… | |
| Analizada | Media (6.9) | 0.33% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully intercepts adoption-related communications may be… | |
| Analizada | Alta (8.2) | 0.32% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. An attacker who obtains the embedded certificates may be able to impersonate trusted controllers or devices and intercept affected communications. | |
| Analizada | Media (6.9) | 0.68% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+108 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in the Omada adoption protocol. The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption. An attacker may be able to impersonate trusted controllers or managed devices and… | |
| Analizada | Media (6.9) | 0.34% | — | Tp-link Omada Oc200 V3 FirmwareTp-link Omada Oc300 FirmwareTp-link Omada Oc400 FirmwareTp-link Omada Fusion 2.5g Firmware+109 | 3/8/2026 | 29/9/2026 | A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials associated with site management are transmitted using a weak hashing algorithm that does not provide sufficient protection. An attacker who successfully intercepts adoption-related authentication traffic… | |
| Pendiente de análisis | Media (6.9) | 0.29% | — | HP DesignjetAI | 3/8/2026 | 3/8/2026 | Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews. | |
| Analizada | Alta (7.7) | 0.22% | — | Tp-link Omada Fusion 2.5g FirmwareTp-link Omada Er707-m2 FirmwareTp-link Omada Er7206 FirmwareTp-link Omada Er706w Firmware+105 | 3/8/2026 | 29/9/2026 | A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification does not adequately validate that a presented certificate corresponds to the expected cloud controller hostname, which may allow certificate validation protections to be… | |
| Pendiente de análisis | Alta (8.2) | 0.37% | — | Guzzlephp GuzzleAI | 1/8/2026 | 8/9/2026 | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and… | |
| Pendiente de análisis | Alta (8.2) | 0.37% | — | Guzzlephp GuzzleAI | 1/8/2026 | 8/9/2026 | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a… | |
| Pendiente de análisis | Media (6.9) | 0.42% | — | Guzzlephp GuzzleAI | 1/8/2026 | 8/9/2026 | guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie… | |
| Pendiente de análisis | Media (6.9) | 0.37% | — | Guzzlephp GuzzleAI | 1/8/2026 | 8/9/2026 | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct… | |
| Aplazada | Media (5.1) | 0.55% | — | Phpjabbers PHP Poll ScriptAI | 31/7/2026 | 28/8/2026 | A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in version 4.1. | |
| Aplazada | Alta (8.6) | 0.38% | — | Phpjabbers PHP Poll ScriptAI | 31/7/2026 | 28/8/2026 | A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1. | |
| Aplazada | Media (6.9) | 0.22% | — | Phpjabbers PHP JabbersAI | 31/7/2026 | 29/9/2026 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized administrative actions, such as creating… | |
| Aplazada | Alta (8.6) | 0.38% | — | Phpjabbers PHP JabbersAI | 31/7/2026 | 29/9/2026 | An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue was fixed in the versions specified in… |