Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
9809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Peachpayments Wc-peach-payments-gatewayAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in peachpayments Peach Payments Gateway wc-peach-payments-gateway allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Peach Payments Gateway: from n/a through <= 4.0.2. | |
| Aplazada | Alta (7.1) | 0.20% | — | Secureage CatchpulseAI | 12/7/2026 | 14/7/2026 | A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. The affected element is an unknown function in the library saappctl.sys of the component Driver. Such manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and… | |
| Aplazada | Media (6.9) | 0.36% | — | PhpmyfaqAI | 10/7/2026 | 10/7/2026 | phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated attackers to retrieve inactive (draft or review-only) FAQ content. Specifically, GET /api/v3.1/faq/{categoryId}/{faqId} returns the inactive FAQ title and full answer,… | |
| Aplazada | Media (5.1) | 0.40% | — | PhpmyfaqAI | 10/7/2026 | 10/7/2026 | phpMyFAQ before 4.1.5 contains a potential authenticated path traversal vulnerability in the concatenatePaths() function within src/phpMyFAQ/Export/Pdf/Wrapper.php. A user with FAQ editing privileges can store HTML containing crafted image paths that are processed during PDF generation. The path resolution logic… | |
| Analizada | Media (5.1) | 0.49% | — | Cakephp | 9/7/2026 | 13/7/2026 | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() method contains a weakness to backslash bypasses that allows redirect targets with attacker-controlled hostnames through the redirect query string… | |
| Analizada | Media (6.1) | 0.17% | — | Guzzlephp Guzzle | 8/7/2026 | 13/7/2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie… | |
| Analizada | Media (6.5) | 0.32% | — | Guzzlephp Psr-7 | 8/7/2026 | 17/7/2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing… | |
| Pendiente de análisis | Media (6.5) | 0.46% | — | HPE Networking Instant ON 1830AIHPE Networking Instant ON 1930AIHPE Networking Instant ON 1960AI | 7/7/2026 | 9/7/2026 | An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow an unauthenticated remote threat actor to access sensitive cryptographic secrets on a vulnerable system. | |
| Pendiente de análisis | Alta (7.5) | 0.46% | 💥 PoC | HP DeskjetAI | 6/7/2026 | 31/8/2026 | Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenticated attacker to access sensitive information through exposed APIs. | |
| Aplazada | Alta (8.7) | 0.55% | — | Elixir-mint HpaxAI | 6/7/2026 | 6/7/2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer decoding. hpax decodes HPACK variable-length integers with no upper bound on the decoded value or the number of continuation octets. 'Elixir.HPAX.Types':decode_remaining_integer/3… | |
| Aplazada | Media (5.5) | 0.69% | — | Jairiidriss Restaurant-website-php-mysqlAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried… | |
| Aplazada | Baja (2.3) | 0.38% | — | PhpipamAI | 4/7/2026 | 6/7/2026 | PHPIPAM is affected by an authenticated local file inclusion vulnerability that allows users with access to the API to execute/include arbitrary PHP files on the web server's file system. The API is not enabled by default on installations. | |
| Analizada | Media (5.3) | 0.28% | — | PHPDebian Linux | 3/7/2026 | 8/7/2026 | In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for… | |
| Pendiente de análisis | Crítica (9.8) | 1.2% | — | HplipAI | 3/7/2026 | 21/8/2026 | A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAIPHPAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php jobs/transcribe.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Guardian Language-systemAIPHPAI | 1/7/2026 | 14/7/2026 | Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php jobs/complex.php \".$login_session.\" \".$_GET['id'].\" ...\"). No authentication is required. An unauthenticated remote attacker can append shell metacharacters to… | |
| Aplazada | Alta (8.7) | 0.44% | — | PhpmyfaqAI | 30/6/2026 | 2/7/2026 | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups without verifying they hold those rights themselves. A delegated administrator can exploit this by assigning high-value permissions to a… | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | HP FAN Control APPAI | 30/6/2026 | 2/7/2026 | — | |
| Aplazada | Alta (8.7) | 0.64% | — | PhpuploaderAI | 29/6/2026 | 14/7/2026 | phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result… | |
| Aplazada | Baja (2.1) | 0.47% | — | Yashpokharna2555 Restaurent-management-systemAI | 28/6/2026 | 29/6/2026 | A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Username results in cross site scripting. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Yashpokharna2555 Restaurent-management-systemAI | 28/6/2026 | 30/6/2026 | A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit is publicly… | |
| Aplazada | Alta (8.8) | 0.52% | — | PHPAIInspirythemes RealhomesAI | 26/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in RealHomes <= 4.5.3 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Buddyboss PlatformAIPHPAI | 26/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. | |
| Aplazada | Alta (7.7) | 0.22% | 💥 PoC | Grocery Store Management System Using PHP AND Mysql PhpmyadminAI | 25/6/2026 | 26/6/2026 | GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | HP Accessory WMI ProviderAIHP Docking StationAI | 24/6/2026 | 26/6/2026 | A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability. |