Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

23.893 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.18%—Ash-project ASH Paper TrailAI30/8/20261/9/2026
Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking,…
AplazadaMedia (5.9)0.12%—Ash-project ASH Paper TrailAI30/8/20261/9/2026
Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the values of tracked sensitive? attributes in the generated version resource's changes…
AplazadaCrítica (9.3)0.78%—Argoproj Argo RolloutsAI28/8/202624/9/2026
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all…
AnalizadaMedia (5.3)0.29%—Morgan Project Morgan28/8/202631/8/2026
morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An unauthenticated remote client can place…
AplazadaMedia (5.3)0.32%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20261/9/2026
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.
AplazadaCrítica (9.8)0.51%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
AplazadaCrítica (9.8)0.51%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application…
AplazadaMedia (6.5)0.35%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.
AplazadaMedia (5.3)0.36%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.
AplazadaAlta (8.1)0.53%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.
AplazadaMedia (5.3)0.34%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20269/9/2026
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.
AplazadaMedia (6.5)0.54%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
AplazadaCrítica (9.1)0.50%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.
AplazadaMedia (5.3)0.36%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20261/9/2026
User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.
AnalizadaMedia (5.4)0.26%—Zephyrproject Zephyr26/8/202631/8/2026
The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In tlv_mgmt_post_recv(), the PTP_MGMT_TIME case casts mgmt_tlv->data to a 10-byte struct ptp_timestamp and reads it (then byte-swaps and writes it back) without first checking that the TLV data field is…
AnalizadaBaja (3.1)0.26%—Zephyrproject Zephyr26/8/202631/8/2026
The LoRaWAN TS004 Fragmented Data Block Transport handler frag_transport_package_callback() in subsys/lorawan/services/frag_transport.c parses downlink command bytes without validating that enough payload bytes remain before each access. The loop's only bound is rx_pos < len; after consuming the one-byte command id…
AnalizadaMedia (4.3)0.24%—Zephyrproject Zephyr26/8/202631/8/2026
The LoRaWAN application-layer clock-synchronization service parses downlinks in clock_sync_package_callback() (subsys/lorawan/services/clock_sync.c). Its command loop only guarantees that the one-byte command id is in bounds; for the CLOCK_SYNC_CMD_APP_TIME (AppTimeAns) command the handler then reads a 4-byte time…
AplazadaMedia (4.3)0.27%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in one of its REST API routes, allowing any authenticated user, such as a subscriber, to read any other user's activity history along with their email address and the details…
AplazadaMedia (5.4)0.23%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.
AplazadaAlta (7.5)0.40%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.
AplazadaMedia (5.3)0.22%—Saasproject Booking PackageAI26/8/202626/8/2026
The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a service's real price.
AplazadaMedia (4.6)0.15%—Corvusproject CorvusskkAI26/8/202628/8/2026
CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.
AplazadaMedia (5.5)0.43%—Code-projects Simple Inventory SystemAI25/8/202626/8/2026
A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be…
AplazadaBaja (2.1)0.47%—Code-projects Online Shopping SystemAI25/8/202626/8/2026
A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/sumit_form.php. Such manipulation of the argument Success leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the…
Pendiente de análisisMedia (5.9)0.51%—Zephyrproject ZephyrAI25/8/202626/8/2026
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without checking the strtok_r return value. When the server-supplied uid is empty or contains no - delimiter,…