Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

23.382 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.8)0.21%—SOS Project SOSAI25/8/20266/10/2026
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly…
Pendiente de análisisMedia (6.5)0.78%—389 Project 389 DS BaseAI25/8/20268/9/2026
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for…
AnalizadaAlta (8.1)0.23%—HBS Project HBS25/8/20266/10/2026
hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after rendering hbs substitutes the placeholder…
AplazadaMedia (6.5)0.38%—WP Project Manager PROAI25/8/202628/9/2026
The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaAlta (7.1)0.41%—Gitpython Project Gitpython25/8/20262/9/2026
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents…
AnalizadaAlta (8.7)0.65%—Gitpython Project Gitpython25/8/20262/9/2026
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled…
AnalizadaCrítica (9.3)0.78%—Gitpython Project Gitpython25/8/20262/9/2026
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write,…
AnalizadaAlta (8.6)0.18%—Gitpython Project Gitpython25/8/20262/9/2026
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is…
AplazadaCrítica (9.8)0.56%—Wedevs WP Project ManagerAI24/8/202627/8/2026
Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
AplazadaAlta (7)0.19%—RansomlookAIPalletsprojects FlaskAI24/8/202626/8/2026
RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting in permissions such as 0644 under a common 022 umask. Consequently, other local users able to access the RansomLook home…
AplazadaAlta (8.7)0.45%—RansomlookAIRocket.chatAIBlueskyAIJoinmastodon MastodonAI+124/8/202626/8/2026
RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim posts to external notification channels. The post-processing logic checks whether an individual post is marked private but does not verify whether the group or market to which the post belongs is…
AplazadaAlta (8.5)0.36%—WP Project Manager PROAI24/8/202624/8/2026
Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
AplazadaBaja (2.1)0.38%—Code-projects Barangay Resident Profiling Management SystemAI23/8/202626/8/2026
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipulation of the argument ID leads to authorization bypass. The attack can be…
AplazadaMedia (5.5)0.43%—Code-projects Barangay Resident Profiling Management SystemAI23/8/202624/8/2026
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The…
AplazadaBaja (2.1)0.38%—Code-projects Barangay Resident Profiling Management SystemAI23/8/202624/8/2026
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The manipulation of the argument resident_id results in authorization bypass. The attack may be launched remotely. The…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management System ProjectAIPHPAI23/8/202624/8/2026
A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.php. This manipulation of the argument delid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
AplazadaAlta (8.5)1.2%—UAC Project UACAI21/8/202624/9/2026
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_artifact.sh where usernames and home directories from /etc/passwd are substituted directly into command strings without escaping before execution via eval. Attackers can…
AplazadaAlta (8.7)0.47%—Misp-project Misp StixAI21/8/202626/8/2026
A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code used sys.exit() to handle several parsing and loading failures. Because SystemExit inherits from BaseException rather than Exception, these failures bypassed the exception…
AnalizadaCrítica (9.3)0.35%—Torproject TOR20/8/20268/9/2026
tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially major for directory authorities. This is TROVE-2026-019.
AnalizadaAlta (8.2)0.35%—Torproject TOR20/8/20268/9/2026
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the…
AnalizadaMedia (5.3)0.38%—Torproject TOR20/8/20268/9/2026
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning…
AnalizadaMedia (5.3)0.39%—Torproject TOR20/8/20268/9/2026
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
AnalizadaCrítica (9)0.30%—Torproject TOR20/8/202616/9/2026
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
AnalizadaAlta (7.5)0.40%—Torproject TOR20/8/202616/9/2026
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.
AnalizadaAlta (8.2)0.25%—Torproject TOR20/8/202616/9/2026
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a…