Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2768 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.43% | — | Google FirebaseAIWeb3formsAI | 12/3/2026 | 17/6/2026 | NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. Prior to 2.0.0, a security vulnerability was identified where Firebase and Web3Forms API keys were exposed. An attacker could use these keys to interact with backend services without authentication,… | |
| Aplazada | Media (5.3) | 0.38% | — | Sourcecodester Web-based Pharmacy Product Management SystemAI | 12/3/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown function of the file add_admin.php. Such manipulation leads to improper authorization. The attack may be launched remotely. | |
| Analizada | Media (4.8) | 0.22% | — | Supabase Auth | 11/3/2026 | 17/6/2026 | Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue sessions for arbitrary users using specially crafted ID tokens when the Apple or Azure providers are enabled. The attacker issues a valid, asymmetrically… | |
| Analizada | Crítica (9.1) | 2.2% | 💥 Exploit | Budibase | 9/3/2026 | 17/6/2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Budibase server's authorized() middleware that protects every server-side API endpoint can be completely bypassed by appending a webhook path pattern to the query string of any request. The… | |
| Analizada | Alta (8.1) | 0.33% | — | Budibase | 9/3/2026 | 17/6/2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path traversal vulnerability in the PWA (Progressive Web App) ZIP processing endpoint (POST /api/pwa/process-zip) allows an authenticated user with builder privileges to read arbitrary files from the… | |
| Analizada | Crítica (9) | 0.40% | — | Budibase | 9/3/2026 | 17/6/2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbitrary file upload vulnerability exists even though file extension restrictions are configured. The restriction is enforced only at the UI level. An attacker can bypass these restrictions and upload… | |
| Analizada | Alta (8.7) | 0.30% | — | Budibase | 9/3/2026 | 17/6/2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of Vertical Privilege Escalation and IDOR (Insecure Direct Object Reference) due to missing server-side RBAC checks in the /api/global/users endpoints. A Creator-level user, who should have no… | |
| Analizada | Alta (8.6) | 0.49% | — | Budibase | 9/3/2026 | 17/6/2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the PostgreSQL integration constructs shell commands using user-controlled configuration values (database name, host, password, etc.) without proper sanitization. The password and other connection… | |
| Analizada | Baja (2) | 0.35% | — | Senior-walter Web-based Pharmacy Product Management System | 8/3/2026 | 17/6/2026 | A security flaw has been discovered in SourceCodester Web-based Pharmacy Product Management System 1.0. This impacts an unknown function of the file edit-profile.php. Performing a manipulation of the argument fullname results in cross site scripting. The attack may be initiated remotely. The exploit has been released… | |
| Analizada | Media (5.5) | 0.57% | — | Lerouxyxchire Client Database Management System | 8/3/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /superadmin_user_update.php. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.70% | — | Lerouxyxchire Client Database Management System | 8/3/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The manipulation of the argument manager_id leads to improper authorization. It is possible to initiate the attack remotely.… | |
| Analizada | Baja (2.1) | 0.46% | — | Lerouxyxchire Client Database Management System | 8/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /superadmin_user_delete.php of the component Endpoint. Executing a manipulation of the argument user_id can lead to improper authorization. The attack may be performed from remote. The… | |
| Analizada | Media (5.5) | 0.57% | — | Lerouxyxchire Client Database Management System | 8/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of the argument manager_id causes improper authorization. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Alta (7.5) | 0.34% | — | ZIP Code Based Content ProtectionAI | 7/3/2026 | 17/6/2026 | The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.2 via the 'zipcode' parameter. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Database FOR Contact Form 7AI | 5/3/2026 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known… | |
| Analizada | Media (5.3) | 0.37% | 💥 PoC | MariadbAmazon Aurora MysqlAmazon Relational Database Service | 3/3/2026 | 14/7/2026 | In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged. | |
| Analizada | Media (5.3) | 4.5% | — | Phialsbasement MCP Nmap Server | 3/3/2026 | 17/6/2026 | A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected by this issue is the function child_process.exec of the file src/index.ts of the component Nmap CLI Command Handler. The manipulation results in command injection. The attack may be performed from… | |
| Analizada | Baja (1.3) | 0.51% | — | Senior-walter Web-based Pharmacy Product Management System | 2/3/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part. This manipulation causes session expiration. Remote exploitation of the attack is possible. The complexity of an attack is rather high. It is indicated that the exploitability is difficult.… | |
| Analizada | Crítica (9) | 0.56% | — | Budibase | 25/2/2026 | 17/6/2026 | Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability in Budibase's view filtering implementation allows any authenticated user (including free tier accounts) to execute arbitrary JavaScript code on the server. This… | |
| Aplazada | Alta (7.2) | 1.2% | — | 389 Project 389 DS BaseAI | 23/2/2026 | 30/6/2026 | A flaw was found in the 389-ds-base server. A heap buffer overflow vulnerability exists in the `schema_attr_enum_callback` function within the `schema.c` file. This occurs because the code incorrectly calculates the buffer size by summing alias string lengths without accounting for additional formatting characters.… | |
| Analizada | Media (6.5) | 0.46% | — | Metabase | 21/2/2026 | 17/6/2026 | Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to retrieve sensitive information from a Metabase instance, including database access credentials. During testing, it was confirmed that a low-privileged user can extract… | |
| Aplazada | Crítica (9.8) | 0.36% | — | Database Software Training Consulting LTD Databank Accreditation SoftwareAI | 19/2/2026 | 25/6/2026 | Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation Software: before 2026/04. | |
| Aplazada | Media (4.3) | 0.19% | — | Echoplugins Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in echoplugins Knowledge Base for Documentation, FAQs with AI Assistance echo-knowledge-base allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Knowledge Base for Documentation, FAQs with AI Assistance: from n/a through <= 16.011.0. | |
| Aplazada | Baja (2.1) | 0.39% | — | Huanzi-qch Base-adminAI | 18/2/2026 | 17/6/2026 | A vulnerability was detected in huanzi-qch base-admin up to 57a8126bb3353a004f3c7722089e3b926ea83596. Impacted is the function Upload of the file SysFileController.java of the component JSP Parser. Performing a manipulation of the argument File results in unrestricted upload. The attack can be initiated remotely. The… | |
| Aplazada | Media (4.3) | 0.17% | — | Keybase IO VerificationAI | 18/2/2026 | 17/6/2026 | The Keybase.io Verification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.5. This is due to missing nonce validation when updating plugin settings. This makes it possible for unauthenticated attackers to update the Keybase verification text via a forged… |